Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.
Published: 2026-10-01
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Data Breach
Action: Immediate Patch
AI Analysis

Impact

An improper neutralization of special elements within an SQL command has been found in the Ultimate Member WordPress plugin, allowing an attacker to perform blind SQL injection attacks. The vulnerability, identified as CWE-89, can lead to unauthorized disclosure, modification, or deletion of database contents, thereby compromising the confidentiality and integrity of the site’s data.

Affected Systems

WordPress sites using the Ultimate Member plugin up to version 2.13.1 are affected. The plugin is distributed under the vendor name Ultimate Member, and all releases from the initial version through 2.13.1 contain the flaw. Upgrading to version 2.14.0 or later removes the vulnerability.

Risk and Exploitability

With a CVSS score of 7.6 the vulnerability is considered high severity, though its EPSS score is currently unavailable and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would exploit the vulnerability through the plugin’s web interface by sending malicious input that is not properly sanitized. The lack of an EPSS evaluation means the current risk of exploitation is uncertain, but the high CVSS score indicates that addressing the vulnerability promptly remains a priority.

Generated by OpenCVE AI on October 1, 2026 at 14:56 UTC.

Remediation

Vendor Solution

Update the WordPress Ultimate Member plugin to the latest available version (at least 2.14.0).


OpenCVE Recommended Actions

  • Apply the latest Ultimate Member plugin update (2.14.0 or newer).
  • Restrict access to Ultimate Member administrative pages to trusted users and enforce strong authentication.
  • Remove or disable unused Ultimate Member features that may expose vulnerable endpoints.

Generated by OpenCVE AI on October 1, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.
Title WordPress Ultimate Member plugin <= 2.13.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T13:57:56.421Z

Reserved: 2026-07-13T06:14:43.014Z

Link: CVE-2026-62059

cve-icon Vulnrichment

Updated: 2026-10-01T13:57:50.695Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T13:17:10.010

Modified: 2026-10-01T14:34:35.357

Link: CVE-2026-62059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:00:12Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')