CVE-2025-12778: Ultimate Member Widgets for Elementor <= 2.3 - Missing Authorization to Unauthenticated Information Exposure
The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handlefilterusers function in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to extract partial metadata of all WordPress users, including their first name, last name and email addresses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12778?
CVE-2025-12778 has a medium severity rating due to unauthorized access to user data.
How do I fix CVE-2025-12778?
To fix CVE-2025-12778, update the Ultimate Member Widgets for Elementor plugin to version 2.4 or later.
What versions of the Ultimate Member Widgets for Elementor are affected by CVE-2025-12778?
All versions up to and including 2.3 of the Ultimate Member Widgets for Elementor are affected by CVE-2025-12778.
Is CVE-2025-12778 an authenticated or unauthenticated vulnerability?
CVE-2025-12778 is an unauthenticated vulnerability, allowing unauthorized users to access data.
What does CVE-2025-12778 exploit in the Ultimate Member Widgets for Elementor plugin?
CVE-2025-12778 exploits a missing capability check in the handle_filter_users function.