Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the registering user's 'submitted' usermeta via update_user_meta() and is only triggered when an administrator opens the affected user record in the wp-admin Users modal, which inserts the unescaped output via jQuery .html().
Published: 2026-10-03
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Stored XSS
Action: Patch
AI Analysis

Impact

The vulnerability allows attackers to inject malicious JavaScript into the stored usermeta field via the form_id parameter. Because the plugin does not sanitize or escape this input, the payload is saved and later rendered when an administrator opens the user record in the wp‑admin Users modal using jQuery .html(). This can execute arbitrary scripts in the context of the administrator’s browser, potentially stealing credentials, performing privilege‑escalating actions, or modifying site data, thereby compromising confidentiality, integrity, and availability of the site’s administrative functions.

Affected Systems

All WordPress sites that have installed the Ultimate Member plugin, version 2.13.1 or earlier, are affected. The vulnerability exists in all releases up to and including 2.13.1 of the plugin.

Risk and Exploitability

The CVSS score of 7.2 classifies this flaw as a high‑severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit the issue via a standard web request that submits a malicious form_id value. Once an administrator visits the corresponding user modal, the stored payload is injected into the page and executed. Because this attack vector requires only HTTP access to the site, the likelihood of exploitation is significant for sites with the vulnerable plugin installed.

Generated by OpenCVE AI on October 3, 2026 at 03:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ultimate Member to version 2.14.0 or later.
  • If an upgrade is not immediately possible, modify the plugin code to validate the form_id input and escape all output from the usermeta when rendering it, ensuring that any stored data is treated as safe HTML.
  • Deploy a web application firewall rule that blocks or sanitizes malicious input for the form_id parameter to mitigate the risk until the plugin is updated.

Generated by OpenCVE AI on October 3, 2026 at 03:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the registering user's 'submitted' usermeta via update_user_meta() and is only triggered when an administrator opens the affected user record in the wp-admin Users modal, which inserts the unescaped output via jQuery .html().
Title Ultimate Member <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'form_id' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:47.558Z

Reserved: 2026-09-22T20:34:09.429Z

Link: CVE-2026-96270

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:51.857Z

cve-icon NVD

Status : Received

Published: 2026-10-03T03:16:37.687

Modified: 2026-10-03T16:16:46.807

Link: CVE-2026-96270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T04:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')