Impact
The vulnerability is an improper control of code generation that lets an attacker trigger an arbitrary function call via the Ultimate Member plugin. This code injection flaw could allow execution of arbitrary functions, potentially leading to the execution of malicious code or unauthorized server behavior. The weakness is identified as CWE-94.
Affected Systems
This issue affects all installations of the Ultimate Member WordPress plugin from the earliest releases through version 2.10.3. Users running any of those versions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 places this vulnerability in the medium range, and the EPSS score indicates a very low, but non-zero, likelihood of exploitation. It is not listed in the current CISA KEV catalog. Attackers would need to craft a request that exploits the plugin’s function call handling, which is reachable over the web; successful exploitation could provide remote code execution. No authentication or elevated privileges are required beyond normal access to the vulnerable site.
OpenCVE Enrichment
EUVD