Description
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership version 1.3.64 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.65 or latest
References
Related Vulnerabilities
WordPress Plugin VideoWhisper Video Presentation 'c_status.php' SQL Injection (1.1)
WordPress Plugin Contact Form 7 Arbitrary File Upload (5.3.1)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-2890)
WordPress Plugin Sliced Invoices-WordPress Invoice Multiple Vulnerabilities (3.8.2)