CVE-2026-96451: WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ultimate Member pluginto a version that resolves this vulnerability.Fixed in 2.14.0
Event History
Frequently Asked Questions
Which installations are affected?
Ultimate Member versions through 2.13.1 are affected. The available data does not identify a fixed version.
What access does an attacker need?
The CVSS vector indicates low privileges are required and no user interaction is needed. The attack can be conducted over the network with low attack complexity.
What is the potential impact?
Successful exploitation can result in privilege escalation and has high confidentiality, integrity, and availability impact according to the CVSS metrics.