Impact
The vulnerability resides in Ultimate Member plugin versions up to and including 2.11.3. Incorrectly configured access control levels allow an attacker to perform actions that should be restricted to privileged users. This can lead to unauthorized modification of user profiles, sensitive data exposure, and potential control over site settings. The weakness is a missing authorization check, classified as CWE-862.
Affected Systems
Ultimate Member plugin for WordPress (versions up to 2.11.3). No additional vendor or product details are provided beyond this range of versions.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the nature of the plugin and the description, the likely attack vector is through the web interface, where an attacker could manipulate requests to bypass the missing authorization checks. No explicit prerequisites are stated, but the presence of the plugin on a WordPress site is required for exploitation.
OpenCVE Enrichment