SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15302

MEDIUM · CVSS 5.3 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The ARMember plugin for WordPress is susceptible to a Directory Traversal vulnerability that allows unauthenticated attackers to upload and overwrite files outside the designated upload directory through the 'X-FILENAME' HTTP header. This could lead to unauthorized file manipulation, potentially compromising the integrity of the website. WordPress site administrators using the ARMember plugin should prioritize patching this vulnerability to safeguard against potential exploitation.

CVE
CVE-2026-15302
Severity
MEDIUM
CVSS
5.3
EPSS
0.53%
WordPress

Original NVD Description

The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the 'wp-content/uploads/armember' directory.