Indicator
Type cve · source NVD CVE
Enrichment by provider
Grouped attempts with latest status; expand for attempt history.
4 attempts · first 2026-07-10T14:30:10.445905Z · last 2026-07-21T19:33:52.017345Z
Not listed in CISA KEV (local)
Types: cisa_kev
4 attempts · first 2026-07-10T14:30:10.437895Z · last 2026-07-21T19:33:52.008817Z
EPSS=0.00533
Types: epss
4 attempts · first 2026-07-10T14:30:10.448985Z · last 2026-07-21T19:33:52.020885Z
The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the 'wp-content/uploads/armember' directory. · CWEs: CWE-36
Types: nvd_local
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
See edges, pivots, and corroboration at a glance.
Full inspector with neighbor expansion.