CVE-2026-96270: Ultimate Member <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'form_id' Parameter
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'formid' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the registering user's 'submitted' usermeta via updateusermeta() and is only triggered when an administrator opens the affected user record in the wp-admin Users modal, which inserts the unescaped output via jQuery .html().
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
WordPress sites using Ultimate Member versions up to and including 2.13.1 are affected. An attacker does not need authentication to submit the malicious form_id value.
What must happen for the injected script to execute?
The payload is stored in the registering user's submitted usermeta. It executes only when an administrator opens that affected user's record in the wp-admin Users modal, where the value is inserted with jQuery .html().
What is the likely impact if exploitation succeeds?
Because the script executes in an administrator's browser within wp-admin, an attacker can run arbitrary web scripts in that administrator's session. The provided severity vector rates confidentiality and integrity impact as low and availability impact as none.
How can administrators identify potentially affected records?
Review Ultimate Member registration user records, particularly the submitted usermeta associated with registering users, for unexpected or script-like form_id values. The provided data identifies that usermeta as the storage location for the injected payload.