Unauthorized Role Assignment in Ultimate Member WordPress Plugin
CVE-2026-19423
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 28 August 2026
Badges
What is CVE-2026-19423?
The Ultimate Member WordPress plugin, prior to version 2.13.0, is susceptible to an improper input validation issue that allows unauthenticated users to manipulate role selections on their profile forms. Instead of validating the selected roles against a specific allow-list, the plugin incorrectly checks these values against the site's registered role names. This flaw could permit unauthorized individuals to assign themselves arbitrary capabilities, potentially granting them administrator-equivalent access without proper authentication.
Affected Version(s)
Ultimate Member 2.6.7 < 2.13.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved