First published: Tue Jul 04 2023(Updated: )
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ultimate Member | <2.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-3460.
The severity of CVE-2023-3460 is critical.
The affected software of CVE-2023-3460 is the Ultimate Member WordPress plugin before version 2.6.7.
An attacker can exploit CVE-2023-3460 by creating user accounts with arbitrary capabilities, effectively allowing them to create administrator accounts at will.
Yes, CVE-2023-3460 is actively being exploited in the wild.