Impact
The vulnerability arises because the Ultimate Member WordPress plugin, before version 2.12.0, fails to properly sanitize and escape custom textarea profile fields. Authenticated users holding Subscriber‑level access or higher can inject JavaScript that executes whenever any user—including administrators—views the affected profile. This CWE‑79 weakness allows an attacker to run code in the victim’s browser context, potentially enabling cookie theft, session hijacking, or other malicious actions against the profile owner. The CVSS score of 8 indicates a high likelihood of significant impacts on confidentiality, integrity, and availability for site users.
Affected Systems
All WordPress sites that have installed Ultimate Member prior to version 2.12.0, particularly those using custom textarea profile fields. The version information is not explicitly specified in the CVE, so any installation of the plugin earlier than 2.12.0 is considered vulnerable.
Risk and Exploitability
With an EPSS score of less than 1%, current public exploitation probability is low, and the vulnerability does not appear in the CISA KEV catalog. Nevertheless, exploitation requires an authenticated account with Subscriber access, which is commonly available in many sites. Once injected, the script runs under the attacker’s control whenever the composite profile is viewed, creating a reliable and persistent attack vector that can affect administrators and other privileged users.
OpenCVE Enrichment