Impact
The vulnerability exists in the Ultimate Member WordPress plugin versions before 2.13.0. It occurs when the plugin fails to verify that a comment has been approved or that the owning profile is private before serving profile activity to visitors. As a result, unauthenticated users can read the bodies of comments that are still awaiting moderation, exposing content that should be restricted. This failure in data confidentiality and access control results in unintended disclosure of potentially sensitive user input.
Affected Systems
Sites running the Ultimate Member plugin at any version older than 2.13.0 are affected. The plugin is commonly installed on WordPress installations that allow user profiles and comment submission. Any platform using an affected plugin version is at risk, regardless of operating system or WordPress core version.
Risk and Exploitability
The vulnerability is exploitable via a simple unauthenticated HTTP request to the profile activity endpoint; no credentials or special user roles are required. The CVSS score is 5.3, indicating medium severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. An attacker who discovers a site running an old Ultimate Member plugin can craft a request to retrieve pending comment text, making the risk realistic and the exploitation straightforward.
OpenCVE Enrichment