CVE-2022-3384

HIGH

Ultimate Member <2.5.0 - Authenticated RCE

Title source: llm
STIX 2.1

Description

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP functions like phpinfo(); since user supplied parameters are not passed through the function. This makes it possible for authenticated attackers, with administrative privileges, to execute code on the server.

Scores

CVSS v3 7.2
EPSS 0.0273
EPSS Percentile 84.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
ultimatemember/Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin < 2.5.0
ultimatemember/ultimate_member < 2.5.0
Published Nov 29, 2022
Tracked Since Feb 18, 2026