{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/user-access-manager--2.3.15/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-18352"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["User Access Manager (\u003c= 2.3.15)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe User Access Manager plugin for WordPress, in versions up to and including 2.3.15, contains a critical directory traversal vulnerability. This flaw allows unauthenticated attackers to read sensitive files from the underlying server filesystem. The vulnerability exists due to improper validation within the handling of the 'uamgetfile' parameter. Specifically, when the function attachment_url_to_postid() fails to resolve a traversal path, the plugin incorrectly falls back to a global post set by a provided 'attachment_id' parameter. This logic error allows an attacker to supply a valid public 'attachment_id' to pass initial security checks, while simultaneously supplying a traversal path in the 'uamgetfile' parameter, which the server then streams to the attacker. This impacts any WordPress environment utilizing this plugin for file access management, potentially leading to the disclosure of configuration files, database credentials, or system sensitive data.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs reconnaissance to identify a target running the vulnerable version of the User Access Manager plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies a valid, publicly accessible 'attachment_id' via standard WordPress enumeration or previous discovery.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP GET request targeting the plugin's file retrieval endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes the legitimate 'attachment_id' to satisfy the plugin's security validation logic.\u003c/li\u003e\n\u003cli\u003eThe attacker injects a directory traversal string (e.g., ../../../etc/passwd) into the 'uamgetfile' parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin's logic fails to correctly associate the traversal path with the attachment ID, improperly falling back to the valid ID while processing the traversal path.\u003c/li\u003e\n\u003cli\u003eThe server application reads the file content from the specified traversal path and transmits it back to the attacker in the HTTP response.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary files on the web server. This can lead to the exposure of WordPress configuration files (wp-config.php), environment variables, database credentials, or other system files. Depending on the server configuration, this could provide an attacker with sufficient information to escalate privileges or gain remote code execution, impacting the integrity and confidentiality of the entire hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the User Access Manager plugin to a version patched against CVE-2026-18352.\u003c/li\u003e\n\u003cli\u003eAudit webserver access logs for anomalous requests containing directory traversal sequences (e.g., \u0026quot;../\u0026quot;) targeting the URL endpoints associated with the User Access Manager plugin.\u003c/li\u003e\n\u003cli\u003eRestrict file access at the web server level (e.g., Nginx or Apache configuration) to prevent unauthorized traversal outside of the designated web root or expected directories.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect attempts to exploit CVE-2026-18352 in real-time.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-02T01:08:24Z","date_published":"2026-08-02T01:08:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-uam-directory-traversal/","summary":"An unauthenticated directory traversal vulnerability in the User Access Manager WordPress plugin (CVE-2026-18352) allows attackers to read arbitrary files by bypassing access controls via the uamgetfile parameter.","title":"Directory Traversal Vulnerability in User Access Manager for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-uam-directory-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - User Access Manager (\u003c= 2.3.15)","version":"https://jsonfeed.org/version/1.1"}