Showing 2 vulnerabilities on this page for ultimate_member

Signals CISA KEV Ransomware Nuclei
Ultimate Member vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

CWE-269Jul 4, 20231 related artifact
CVSS9.8v3.1EPSS72.3%PoCs10SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Ultimate Member ultimate_member Improper Privilege Management

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access.

CWE-269Jan 4, 20211 related artifact
CVSS10.0v3.1EPSS8.98%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX