Impact
The Ultimate Member WordPress plugin, before version 2.12.0, does not properly escape custom textarea profile fields. Authenticated users with Subscriber-level access or higher can store JavaScript that runs when anyone, including administrators, views the affected profile, resulting in a stored cross‑site scripting flaw.
Affected Systems
WordPress sites that use the Ultimate Member plugin in any version older than 2.12.0 and that have custom textarea profile fields enabled. The flaw is present in all affected instances regardless of other configuration settings.
Risk and Exploitability
With a CVSS score of 8 the potential impact is high. The EPSS score is below 1 %, indicating a low probability of public exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. However, exploitation requires an authenticated account with at least Subscriber access, a privilege that is commonly available on many sites. Once a user stores malicious code, the script executes in the browser of every visitor to the profile, creating a reliable and persistent attack vector.
OpenCVE Enrichment