Stored Cross-Site Scripting in Ultimate Member Plugin for WordPress
CVE-2026-96270

7.2HIGH

What is CVE-2026-96270?

The Ultimate Member plugin for WordPress is susceptible to a stored Cross-Site Scripting (XSS) vulnerability that arises from inadequate input sanitization and output escaping involving the 'form_id' parameter. Attackers, without authentication, can inject malicious scripts that are stored in the usermeta of the registering user. These scripts can be triggered when an administrator reviews the affected user record in the WordPress admin interface, leading to potential exploitation whenever a user accesses the compromised page.

Affected Version(s)

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 0 <= 2.13.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thevietronin
.