Description
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership version 1.3.64 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.65 or latest
References
Related Vulnerabilities
Envoy Proxy Improper Certificate Validation Vulnerability (CVE-2022-21657)
MySQL CVE-2014-6559 Vulnerability (CVE-2014-6559)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-10890)
Drupal Core 7.x Denial of Service (7.0 - 7.19)
WordPress Plugin Apptivo Business Site CRM Multiple Cross-Site Scripting Vulnerabilities (1.2.9)