QID 730836
Date Published: 2023-07-03
QID 730836: WordPress Plugin Ultimate Member Unauthenticated Privilege Escalation Vulnerability
Ultimate Member user profile and membership plugin for WordPress. The plugin allows you to add beautiful user profiles to your site and is perfect for creating advanced online communities and membership sites.
This plugin allow visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts as well.
Affected Versions:
WordPress Plugin Ultimate Member versions before 2.6.7
QID Detection Logic:
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Ultimate Member WordPress plugin.
Successful exploitation of this vulnerability allows an unauthenticated attacker to register as an administrator and take full control of the website.
- Ultimate Member Plugin Release Notes -
wordpress.org/plugins/ultimate-member/#developers
CVEs related to QID 730836
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ultimate Member Plugin Release Notes |
|