PT-2026-82876 · WordPress · Ultimate Member
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ultimate Member WordPress plugin versions prior to 2.13.0
Description
An issue exists where the plugin fails to validate role selection when it cannot resolve the set of roles permitted by a profile form. Instead of checking against the form's specific allow-list, the system validates the value against the site's registered role names. This allows unauthenticated users registering through the plugin's form to assign themselves arbitrary capabilities, potentially gaining administrator-equivalent access.
Recommendations
Update Ultimate Member WordPress plugin to version 2.13.0 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ultimate Member