Impact
The vulnerability is a stored XSS flaw caused by insufficient sanitization and output escaping in a textarea profile field that accepts HTML. It allows an authenticated user with subscriber‑level or higher access to inject JavaScript that will run when any user views the profile page, potentially enabling session hijacking, defacement, or data exfiltration.
Affected Systems
WordPress sites that have installed the Ultimate Member plugin version 2.12.1 or earlier are impacted. The flaw exists in all releases up to and including 2.12.1 of the Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the vulnerability is exploitable over the web by any authenticated user with subscriber-level privileges. Although EPSS data is unavailable and the issue is not listed in CISA’s KEV catalog, the attack vector is likely straightforward via the user profile editing interface, making it a practical risk for affected sites. Proper authentication is required, but once logged in, an attacker can inject scripts that execute in the context of other users visiting the profile page.
OpenCVE Enrichment