Impact
The ARMember WordPress plugin is vulnerable to directory traversal through the X‑FILENAME HTTP header in all versions up to 4.0.27. A malicious requester can craft a header that causes the plugin to write files outside the intended wp‑content/uploads/armember folder, allowing the upload and overwrite of files such as CSS that are served to site visitors. This flaw permits an unauthenticated attacker to deliver malicious content by tampering with files that affect site appearance and potentially client-side execution.
Affected Systems
The reputeinfosystems:ARMember plugin, versions 4.0.27 and earlier, is affected. No other vendors or products are listed in the CNA data. The issue applies to WordPress sites that have the ARMember plugin installed and have uploads enabled.
Risk and Exploitability
The CVSS score of 5.3 suggests a moderate risk, while the EPSS score of < 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request containing a malicious X‑FILENAME header that bypasses path restrictions, enabling file write operations outside the designated upload directory. The flaw is classified as CWE‑36, Path Traversal.
OpenCVE Enrichment