Impact
The Ultimate Member plugin for WordPress is vulnerable to an authorization bypass in its public AJAX endpoint, allowing attackers to retrieve privacy‑restricted member profile fields. The endpoint wp_ajax_nopriv_um_get_members is accessible to anyone without authentication, and it requires only a nonce that is publicly emitted to all visitors. Because the plugin does not verify the requester's authorization, fields configured as owner‑only, members‑only, or role‑restricted can be read by any anonymous user. This flaw provides direct access to personal data that should remain confidential, allowing attackers to harvest sensitive information about site members.
Affected Systems
Affected systems include all instances of the Ultimate Member plugin up to and including version 2.13.1; any WordPress site running the vulnerable plugin and relying on the privacy controls for member profile fields is at risk.
Risk and Exploitability
Risk and exploitability: The CVSS score of 7.5 indicates a high severity, and the absence of an EPSS score suggests the exploit is likely to occur once discovered because the endpoint is easily discoverable. The vulnerability is not listed in CISA’s KEV catalog, but the public nature of the AJAX endpoint and lack of authentication checks mean exploitation can happen with minimal effort. An attacker only needs to construct a request to the wp_ajax_nopriv_um_get_members endpoint and include an arbitrary valid nonce, which is available to anyone who visits the site. Once the request is made, the service returns member profile data in a format that exposes sensitive fields that should be restricted.
OpenCVE Enrichment