CyberRota Analysis
AI-GeneratedThe ARMember plugin for WordPress is susceptible to a Directory Traversal vulnerability that allows unauthenticated attackers to upload and overwrite files outside the designated upload directory through the 'X-FILENAME' HTTP header. This could lead to unauthorized file manipulation, potentially compromising the integrity of the website. WordPress site administrators using the ARMember plugin should prioritize patching this vulnerability to safeguard against potential exploitation.
Original NVD Description
The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the 'wp-content/uploads/armember' directory.