216.73.217.22

CVE-2020-37169

· Published 13/05/2026 16:16 · Modified 13/05/2026 17:07

Labels: CVE-2020-37169 2026-05-13CVE-2020-37169CWE-98[email protected]

Essential information

Published
13/05/2026 16:16
Modified
13/05/2026 17:07
Author
Creator
CVSS
6.8 MEDIUM (v3) 6.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP files from the packages directory and execute arbitrary code.

NVD status

Status
Deferred — When a CVE is given this status the NVD does not plan analyze or re-analyze this CVE due to resource or other concerns.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ultimate-member / ultimate-member cpe:2.3:a:ultimate-member:ultimate-member:2.1.3:*:*:*:*:*:*:*
wordpress / wordpress cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*

References