WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP files from the packages directory and execute arbitrary code.
Metrics
Affected Vendors & Products
References
History
Wed, 13 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP files from the packages directory and execute arbitrary code. | |
| Title | WordPress Plugin ultimate-member 2.1.3 Local File Inclusion | |
| First Time appeared |
Ultimatemember
Ultimatemember ultimate Member |
|
| Weaknesses | CWE-98 | |
| CPEs | cpe:2.3:a:ultimatemember:ultimate_member:2.1.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Ultimatemember
Ultimatemember ultimate Member |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-13T14:22:28.602Z
Updated: 2026-05-13T15:33:39.501Z
Reserved: 2026-02-06T12:30:45.308Z
Link: CVE-2020-37169
No data.
Status : Deferred
Published: 2026-05-13T16:16:32.747
Modified: 2026-05-13T17:07:21.030
Link: CVE-2020-37169
No data.