CVE-2025-47691: WordPress Ultimate Member plugin <= 2.10.3 - Arbitrary Function Call vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member allows Code Injection. This issue affects Ultimate Member: from n/a through 2.10.3.
Other sources
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47691?
CVE-2025-47691 is recognized as a critical vulnerability due to its potential for code injection.
How do I fix CVE-2025-47691?
To fix CVE-2025-47691, you should update the Ultimate Member plugin to at least version 2.10.4.
What versions of Ultimate Member are affected by CVE-2025-47691?
CVE-2025-47691 affects Ultimate Member versions up to and including 2.10.3.
What type of vulnerability is CVE-2025-47691?
CVE-2025-47691 is classified as a Code Injection vulnerability.
What are the implications of CVE-2025-47691 for users of Ultimate Member?
Users of Ultimate Member are at risk of attackers executing arbitrary code on their websites due to CVE-2025-47691.