Information disclosure in Ultimate Member - User Profile & Membership Plugin - #VU18597
Published: May 24, 2019
Ultimate Member - User Profile & Membership Plugin
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the lack of validation when change the file name wp-config.php from the profile form. A remote authorized attacker can read and delete wp-config.php file to gain unauthorized access to sensitive information on the system.