Description
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a role exists and a role-selection field is present on a published registration form.
Published: 2026-07-31
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Ultimate Member WordPress plugin versions older than 2.12.1. The plugin fails to filter administrator‑level capabilities when populating role options in registration forms. Additionally, the post‑registration safeguard that blocks the creation of privileged accounts is disabled by default. These omissions allow any unauthenticated visitor to register with a role that grants administrator rights, provided such a role exists and a role‑selection field is present on the form. Once registered, the user obtains full site administrative privileges without needing to bypass authentication.

Affected Systems

All WordPress sites that employ the Ultimate Member plugin before version 2.12.1 and expose a registration form containing a role‑selection field are vulnerable. The risk applies to any environment where an administrator role exists that can be chosen during registration, and where the default settings permit role selection.

Risk and Exploitability

The flaw permits unauthenticated privilege escalation, a high‑severity security issue. The EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, and the weakness is not listed in the KEV catalog, the potential impact is significant. Attackers need only access the public registration page and choose an administrative role. No additional credentials or system access are required. Sites that enable the post‑registration safeguard would mitigate the exploit, but the feature is disabled by default.

Generated by OpenCVE AI on August 4, 2026 at 11:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Ultimate Member plugin to version 2.12.1 or later, which corrects the role filtering and re‑enables the safeguard.
  • Ensure that the post‑registration safeguard is enabled or otherwise restrict role selection on public registration forms.
  • Remove any role‑selection fields from registration forms or limit available options to non‑privileged roles to prevent accidental elevation.

Generated by OpenCVE AI on August 4, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 31 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Ultimatemember
Ultimatemember ultimate Member
Wordpress
Wordpress wordpress
Vendors & Products Ultimatemember
Ultimatemember ultimate Member
Wordpress
Wordpress wordpress

Fri, 31 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a role exists and a role-selection field is present on a published registration form.
Title Ultimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Selection Field
References

Subscriptions

Ultimatemember Ultimate Member
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-31T16:55:03.841Z

Reserved: 2026-06-15T08:27:12.663Z

Link: CVE-2026-12251

cve-icon Vulnrichment

Updated: 2026-07-31T16:54:43.918Z

cve-icon NVD

Status : Received

Published: 2026-07-31T07:16:23.240

Modified: 2026-07-31T18:17:09.777

Link: CVE-2026-12251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:30:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management