CVE-2022-3966 - CVE House
Back to Database
Status published Medium CVE-2022-3966

Ultimate Member Plugin Template class-shortcodes.php load_template pathname traversal

Vulnerability Description

A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. The manipulation of the argument tpl leads to pathname traversal. The attack may be initiated remotely. Upgrading to version 2.5.1 is able to address this issue. The name of the patch is e1bc94c1100f02a129721ba4be5fbc44c3d78ec4. It is recommended to upgrade the affected component. The identifier VDB-213545 was assigned to this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3966

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

unspecified

View all reports →

Affected Software

Ultimate Member Plugin
Vulnerable Versions:
2.0, 2.1, 2.2, 2.3, 2.4, 2.5

Timeline

Official Publish: November 13th, 2022
Last Modified: April 15th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)