Impact
An improper neutralization of special elements within an SQL command has been found in the Ultimate Member WordPress plugin, allowing an attacker to perform blind SQL injection attacks. The vulnerability, identified as CWE-89, can lead to unauthorized disclosure, modification, or deletion of database contents, thereby compromising the confidentiality and integrity of the site’s data.
Affected Systems
WordPress sites using the Ultimate Member plugin up to version 2.13.1 are affected. The plugin is distributed under the vendor name Ultimate Member, and all releases from the initial version through 2.13.1 contain the flaw. Upgrading to version 2.14.0 or later removes the vulnerability.
Risk and Exploitability
With a CVSS score of 7.6 the vulnerability is considered high severity, though its EPSS score is currently unavailable and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would exploit the vulnerability through the plugin’s web interface by sending malicious input that is not properly sanitized. The lack of an EPSS evaluation means the current risk of exploitation is uncertain, but the high CVSS score indicates that addressing the vulnerability promptly remains a priority.
OpenCVE Enrichment