Impact
The vulnerability allows attackers to inject malicious JavaScript into the stored usermeta field via the form_id parameter. Because the plugin does not sanitize or escape this input, the payload is saved and later rendered when an administrator opens the user record in the wp‑admin Users modal using jQuery .html(). This can execute arbitrary scripts in the context of the administrator’s browser, potentially stealing credentials, performing privilege‑escalating actions, or modifying site data, thereby compromising confidentiality, integrity, and availability of the site’s administrative functions.
Affected Systems
All WordPress sites that have installed the Ultimate Member plugin, version 2.13.1 or earlier, are affected. The vulnerability exists in all releases up to and including 2.13.1 of the plugin.
Risk and Exploitability
The CVSS score of 7.2 classifies this flaw as a high‑severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit the issue via a standard web request that submits a malicious form_id value. Once an administrator visits the corresponding user modal, the stored payload is injected into the page and executed. Because this attack vector requires only HTTP access to the site, the likelihood of exploitation is significant for sites with the vulnerable plugin installed.
OpenCVE Enrichment