CVE-2020-37169 PUBLISHED

WordPress Plugin ultimate-member 2.1.3 Local File Inclusion

Assigner: VulnCheck
Reserved: 06.02.2026 Published: 13.05.2026 Updated: 13.05.2026

WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP files from the packages directory and execute arbitrary code.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor Ultimate Member
Product ultimate-member
Versions
  • Version 2.1.3 is affected

Credits

  • mehran feizi finder

References

Problem Types

  • Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') CWE