CVE-2020-37169 | Ultimate Member ultimate-member Plugin 2.1.3 on WordPress class-admin-upgrade.php class-admin-upgrade.php. pack filename control (Exploit 48065)
A vulnerability described as critical has been identified in Ultimate Member ultimate-member Plugin 2.1.3 on WordPress. This affects the function class-admin-upgrade.php. of the file class-admin-upgrade.php. Such manipulation of the argument pack leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is documented as CVE-2020-37169. The attack can be executed remotely. Additionally, an exploit exists.