Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nikitasinelnikov

#36294of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2022-24984
7.5
2022-11-13
WordPress · Ultimate Member Plugin · CVE-2022-3966
**Name of the Vulnerable Software and Affected Versions** Ultimate Member Plugin versions up to 2.5.0 **Description** A critical issue has been found in the Template Handler component, specifically affecting the `load template` function of the file `includes/core/class-shortcodes.php`. The manipulation of the `tpl` argument leads to pathname traversal. This issue can be initiated remotely. **Recommendations** For Ultimate Member Plugin versions up to 2.5.0, upgrade to version 2.5.1 to address this issue. As a temporary workaround, consider restricting access to the `load template` function of the `class-shortcodes.php` file until the upgrade is applied.