Description
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership version 1.3.64 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.65 or latest
References
Related Vulnerabilities
Apache HTTP Server Use After Free Vulnerability (CVE-2017-9789)
WordPress Plugin Placemarks Cross-Site Scripting (2.0.0)
WordPress Plugin Ultimate Google Analytics Cross-Site Request Forgery (1.6.0)
Oracle JRE CVE-2013-5790 Vulnerability (CVE-2013-5790)
WordPress Plugin ARPrice-Responsive Pricing Table Cross-Site Scripting (2.2)