Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view privacy-restricted member profile field values — including fields explicitly configured as owner-only, members-only, or role-restricted — by querying the publicly accessible wp_ajax_nopriv_um_get_members endpoint. The nonce required by the endpoint ('um-frontend-nonce') is emitted to all unauthenticated visitors via wp_localize_script, meaning it provides no meaningful access control and any anonymous visitor can satisfy the endpoint's authentication requirements.
Published: 2026-10-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of sensitive user profile data
Action: Immediate patch
AI Analysis

Impact

The Ultimate Member plugin for WordPress is vulnerable to an authorization bypass in its public AJAX endpoint, allowing attackers to retrieve privacy‑restricted member profile fields. The endpoint wp_ajax_nopriv_um_get_members is accessible to anyone without authentication, and it requires only a nonce that is publicly emitted to all visitors. Because the plugin does not verify the requester's authorization, fields configured as owner‑only, members‑only, or role‑restricted can be read by any anonymous user. This flaw provides direct access to personal data that should remain confidential, allowing attackers to harvest sensitive information about site members.

Affected Systems

Affected systems include all instances of the Ultimate Member plugin up to and including version 2.13.1; any WordPress site running the vulnerable plugin and relying on the privacy controls for member profile fields is at risk.

Risk and Exploitability

Risk and exploitability: The CVSS score of 7.5 indicates a high severity, and the absence of an EPSS score suggests the exploit is likely to occur once discovered because the endpoint is easily discoverable. The vulnerability is not listed in CISA’s KEV catalog, but the public nature of the AJAX endpoint and lack of authentication checks mean exploitation can happen with minimal effort. An attacker only needs to construct a request to the wp_ajax_nopriv_um_get_members endpoint and include an arbitrary valid nonce, which is available to anyone who visits the site. Once the request is made, the service returns member profile data in a format that exposes sensitive fields that should be restricted.

Generated by OpenCVE AI on October 3, 2026 at 03:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Ultimate Member plugin to version 2.14.0 or later.
  • Remove or block the wp_ajax_nopriv_um_get_members endpoint for unauthenticated users, for example by adding a rule in a web‑application firewall or by modifying server configuration to deny that URI.
  • Review the privacy settings for all member profile fields and confirm that sensitive data is not configured to be publicly accessible.

Generated by OpenCVE AI on October 3, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view privacy-restricted member profile field values — including fields explicitly configured as owner-only, members-only, or role-restricted — by querying the publicly accessible wp_ajax_nopriv_um_get_members endpoint. The nonce required by the endpoint ('um-frontend-nonce') is emitted to all unauthenticated visitors via wp_localize_script, meaning it provides no meaningful access control and any anonymous visitor can satisfy the endpoint's authentication requirements.
Title Ultimate Member <= 2.13.1 - Missing Authorization to Unauthenticated Sensitive Profile Field Disclosure via Member Directory Field Privacy Bypass
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:46.923Z

Reserved: 2026-09-17T21:02:44.203Z

Link: CVE-2026-93428

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:44.778Z

cve-icon NVD

Status : Received

Published: 2026-10-03T03:16:37.067

Modified: 2026-10-03T16:16:44.037

Link: CVE-2026-93428

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T04:00:12Z

Weaknesses