CVE-2026-19423: Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms

Published Aug 28, 2026
·
Updated

The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant themselves arbitrary capabilities and reach administrator-equivalent access.

Affected Software

1 affected component
WordPress Ultimate Member>=2.6.7<=2.12.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Ultimate Member (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 2.13.0
  2. Compensating control

    Ensure role selection on Ultimate Member profile forms cannot be used by unauthenticated users to set roles/capabilities outside the form's allow-list (e.g., constrain the role field handling so it validates against the form's permitted roles rather than only against site-registered role names).

Event History

Aug 28, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which installations are exposed?

Sites using Ultimate Member versions 2.6.7 through 2.12.1 are affected when users can register through the plugin's own profile form. Version 2.13.0 is not described as affected.

2

What does an attacker need to exploit this issue?

The attacker does not need to be authenticated. They need to register through an Ultimate Member profile form where the plugin cannot resolve the roles permitted by that form.

3

What level of access could exploitation provide?

An attacker can submit a role value that is checked against roles registered on the site rather than the form's allowed roles. This can grant arbitrary capabilities and lead to administrator-equivalent access.

4

What should be prioritized if remediation cannot happen immediately?

The available information identifies registration through Ultimate Member profile forms as the attack path. Prioritize restricting or disabling access to those registration forms until the plugin can be updated to 2.13.0 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203