Vulnerability in Ultimate Member Plugin for WordPress Affects User Data Security
CVE-2025-12492
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 December 2025
What is CVE-2025-12492?
The Ultimate Member Plugin for WordPress is vulnerable to sensitive information exposure due to a poorly designed authentication mechanism in its ajax_get_members function. This issue arises from the use of a low-entropy token structured from MD5 hashed post IDs, which is predictable and allows unauthorized users to enumerate member directory IDs. Consequently, attackers can gain access to sensitive user information, including usernames, display names, user roles (including admin rights), profile URLs, and user IDs, by simply brute-forcing the limited token space or exploiting the inadequate authorization checks in the unauthenticated AJAX endpoint. This vulnerability poses a significant risk to the privacy of users on WordPress sites employing this plugin.
Affected Version(s)
Ultimate Member β User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin * <= 2.11.0