A vulnerability was found in gm_alex User Access Manager Plugin up to 2.3.15 on WordPress. It has been declared as problematic. The affected element is the function
attachment_url_to_postid. The manipulation of the argument uamgetfile results in path traversal.
This vulnerability is cataloged as CVE-2026-18352. The attack may be launched remotely. There is no exploit available.