Impact
The Ultimate Member WordPress plugin prior to version 2.13.0 fails to validate the role selected in registration forms when the plugin cannot resolve the form's allowed roles. This bug causes the plugin to compare the submitted role against the site's registered role names instead of the form's allow‑list, allowing an unauthenticated user to register with any role name, including administrator, thereby gaining full control of the site. The flaw is a direct form‑based privilege escalation that does not require any pre‑existing account or credentials.
Affected Systems
WordPress sites that use the Ultimate Member plugin in versions 2.6.7 through 2.12.1 and that enable public user registration or allow role selection in their profile or registration forms are vulnerable. Sites with the default configuration of the plugin are the most susceptible, particularly those that have not restricted or removed the role field from the form.
Risk and Exploitability
Although no CVSS, EPSS, or KEV data are published for this issue, the nature of the flaw permits an attacker to create an elevated account without any authentication, yielding full administrator capabilities. The likely attack vector would be the public registration or profile form, meaning any visitor to the affected site could exploit this. The potential impact is catastrophic for the site’s confidentiality, integrity, and availability, making the risk extremely high even if exploitation is not currently demonstrated.
OpenCVE Enrichment