Vulnerability Description
The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the 'wp-content/uploads/armember' directory.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/3062692/armember-membership/trunk/c
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2c8734f5-4d23-454d-bf0
FAQ
What is CVE-2026-15302?
CVE-2026-15302 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attacke...
How severe is CVE-2026-15302?
CVE-2026-15302 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15302?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.