The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME'…
Wordfence·CWE-36·Published 2026-07-10