Administrator Role Bypass in Ultimate Member Plugin for WordPress
CVE-2026-12251
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 31 July 2026
Badges
What is CVE-2026-12251?
The Ultimate Member plugin for WordPress before version 2.12.1 allows unauthenticated users to exploit a flaw that does not properly filter administrator-level capabilities from selectable roles during registration. Additionally, the default configuration lacks crucial safeguards against account elevation, which can enable users to register with roles that have full administrative access. If a role-selection field is included on a published registration form, this vulnerability could be exploited, granting unauthorized users administrative privileges.
Affected Version(s)
Ultimate Member 0 < 2.12.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.