CVE-2026-15302 | reputeinfosystems ARMember Plugin up to 4.0.27 on WordPress File Upload /uploads/armember X-FILENAME path traversal
A vulnerability, which was classified as critical, has been found in reputeinfosystems ARMember Plugin up to 4.0.27 on WordPress. Affected by this vulnerability is an unknown functionality of the file /uploads/armember of the component File Upload Handler. The manipulation of the argument X-FILENAME leads to path traversal.
This vulnerability is traded as CVE-2026-15302. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More