CVE-2020-37169
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
13/05/2026
Last modified:
13/05/2026
Description
WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP files from the packages directory and execute arbitrary code.
Impact
Base Score 4.0
6.80
Severity 4.0
MEDIUM
Base Score 3.x
5.50
Severity 3.x
MEDIUM



