Description
The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator, views the affected profile.
Published: 2026-07-06
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ultimate Member WordPress plugin, before version 2.12.0, does not properly escape custom textarea profile fields. Authenticated users with Subscriber-level access or higher can store JavaScript that runs when anyone, including administrators, views the affected profile, resulting in a stored cross‑site scripting flaw.

Affected Systems

WordPress sites that use the Ultimate Member plugin in any version older than 2.12.0 and that have custom textarea profile fields enabled. The flaw is present in all affected instances regardless of other configuration settings.

Risk and Exploitability

With a CVSS score of 8 the potential impact is high. The EPSS score is below 1 %, indicating a low probability of public exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. However, exploitation requires an authenticated account with at least Subscriber access, a privilege that is commonly available on many sites. Once a user stores malicious code, the script executes in the browser of every visitor to the profile, creating a reliable and persistent attack vector.

Generated by OpenCVE AI on August 4, 2026 at 07:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ultimate Member plugin to version 2.12.0 or newer to apply the vendor fix.
  • If an upgrade cannot be performed immediately, disable or delete any custom textarea profile fields until the patch is applied so that no hazardous content can be stored.
  • Apply a content sanitization policy or employ a security plugin that automatically removes JavaScript from custom profile fields before display.

Generated by OpenCVE AI on August 4, 2026 at 07:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 31 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 25 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 22 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 15 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 14 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 13 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 11 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 11 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 08 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 08 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 07 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 07 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 06 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Ultimatemember
Ultimatemember ultimate Member
Wordpress
Wordpress wordpress
Vendors & Products Ultimatemember
Ultimatemember ultimate Member
Wordpress
Wordpress wordpress

Mon, 06 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator, views the affected profile.
Title Ultimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile Fields
References

Subscriptions

Ultimatemember Ultimate Member
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-06T12:02:30.806Z

Reserved: 2026-06-09T09:51:17.031Z

Link: CVE-2026-11766

cve-icon Vulnrichment

Updated: 2026-07-06T12:02:22.314Z

cve-icon NVD

Status : Deferred

Published: 2026-07-06T08:16:35.083

Modified: 2026-07-06T18:37:01.220

Link: CVE-2026-11766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:00:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')