PT-2026-95757 · WordPress · Ultimate Member

·

CVE-2026-85680

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ultimate Member WordPress plugin versions prior to 2.13.1
Description An issue exists where the plugin fails to escape a value derived from user-supplied profile names before outputting it in the page title. Additionally, the software decodes HTML entities after the sanitization process has already been executed. This allows unauthenticated attackers who register an account to store JavaScript that executes when any visitor, including an administrator, views the affected profile.
Recommendations Update Ultimate Member WordPress plugin to version 2.13.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85680

Affected Products

Ultimate Member