Impact
The vulnerability resides in the Ultimate Member WordPress plugin versions older than 2.12.1. The plugin fails to filter administrator‑level capabilities when populating role options in registration forms. Additionally, the post‑registration safeguard that blocks the creation of privileged accounts is disabled by default. These omissions allow any unauthenticated visitor to register with a role that grants administrator rights, provided such a role exists and a role‑selection field is present on the form. Once registered, the user obtains full site administrative privileges without needing to bypass authentication.
Affected Systems
All WordPress sites that employ the Ultimate Member plugin before version 2.12.1 and expose a registration form containing a role‑selection field are vulnerable. The risk applies to any environment where an administrator role exists that can be chosen during registration, and where the default settings permit role selection.
Risk and Exploitability
The flaw permits unauthenticated privilege escalation, a high‑severity security issue. The EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, and the weakness is not listed in the KEV catalog, the potential impact is significant. Attackers need only access the public registration page and choose an administrative role. No additional credentials or system access are required. Sites that enable the post‑registration safeguard would mitigate the exploit, but the feature is disabled by default.
OpenCVE Enrichment