Ultimate Member <2.6.7 - Privilege Escalation
Title source: llmDescription
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.
Exploits (12)
exploitdb
WORKING POC
by Gurjot Singh · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52393
nomisec
WORKING POC
7 stars
by diego-tella · client-side
https://github.com/diego-tella/CVE-2023-3460
github
WORKING POC
3 stars
by certuscyber · pythonpoc
https://github.com/certuscyber/cve-pocs/tree/main/CVE-2023-3460
nomisec
WORKING POC
1 stars
by Rajneeshkarya · remote
https://github.com/Rajneeshkarya/CVE-2023-3460
Nuclei Templates (1)
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
CRITICALVERIFIEDby DhiyaneshDk
Shodan:
http.html:/wp-content/plugins/ultimate-member
FOFA:
body=/wp-content/plugins/ultimate-member
Scores
CVSS v3
9.8
EPSS
0.9281
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+8 more repos
Details
VulnCheck KEV
2023-06-29
InTheWild.io
2023-07-04
Status
published
Products (1)
ultimatemember/ultimate_member
< 2.6.7
Published
Jul 04, 2023
Tracked Since
Feb 18, 2026