Stored Cross-Site Scripting in Ultimate Member Plugin for WordPress
CVE-2026-96270
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-96270?
The Ultimate Member plugin for WordPress is susceptible to a stored Cross-Site Scripting (XSS) vulnerability that arises from inadequate input sanitization and output escaping involving the 'form_id' parameter. Attackers, without authentication, can inject malicious scripts that are stored in the usermeta of the registering user. These scripts can be triggered when an administrator reviews the affected user record in the WordPress admin interface, leading to potential exploitation whenever a user accesses the compromised page.
Affected Version(s)
Ultimate Member β User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 0 <= 2.13.1