CVE-2020-37169 MEDIUM

CVE-2020-37169: WordPress Plugin ultimate-member 2.1.3 Local File Inclusion

Vendor Ultimate Member
Product ultimate-member
Weakness CWE-98 · PHP file inclusion
Published May 13, 2026
Last update May 13, 2026

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

Description

WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP files from the packages directory and execute arbitrary code.

Key dates

Disclosure timeline

May 13, 2026 CVE published
May 13, 2026 Record updated