CVE-2025-13220: Ultimate Member <= 2.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes in all versions up to, and including, 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13220?
CVE-2025-13220 has a severity rating that highlights the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-13220?
To fix CVE-2025-13220, upgrade the Ultimate Member plugin to version 2.11.1 or later.
What versions are affected by CVE-2025-13220?
CVE-2025-13220 affects all versions of the Ultimate Member plugin up to and including version 2.11.0.
What types of attacks can be executed due to CVE-2025-13220?
CVE-2025-13220 can allow attackers to perform Stored Cross-Site Scripting attacks through the plugin’s shortcode attributes.
Is user data at risk due to CVE-2025-13220?
Yes, due to CVE-2025-13220, user data may be at risk from malicious scripts that can be executed within the application.