CVE-2025-0318: Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated attackers to exfiltrate data from wpusermeta table.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0318?
CVE-2025-0318 is classified as a moderate severity vulnerability due to potential information exposure.
How do I fix CVE-2025-0318?
To fix CVE-2025-0318, update the Ultimate Member plugin to version 2.9.2 or later.
What versions are affected by CVE-2025-0318?
CVE-2025-0318 affects all versions of the Ultimate Member plugin up to and including version 2.9.1.
What type of vulnerability is CVE-2025-0318?
CVE-2025-0318 is an information exposure vulnerability causing potential leakage of sensitive data through error messages.
Can CVE-2025-0318 affect my WordPress site?
Yes, if your WordPress site uses an affected version of the Ultimate Member plugin, it is susceptible to CVE-2025-0318.