PT-2026-66684 · WordPress · Ultimate Member

·

CVE-2026-12251

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ultimate Member WordPress plugin versions prior to 2.12.1
Description The plugin fails to filter administrator-level capabilities from the roles available for selection on registration forms. Additionally, the post-registration safeguard designed to prevent the creation of elevated accounts is disabled by default. This allows unauthenticated users to register with a site-defined role that possesses administrator capabilities, granting them full administrative access to the site, provided such a role exists and a role-selection field is active on a published registration form.
Recommendations Update Ultimate Member WordPress plugin to version 2.12.1 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12251

Affected Products

Ultimate Member