high · CVSS v3 7.5
CVE-2026-93428
The Ultimate Member plugin for WordPress has an authorization bypass that allows unauthenticated users to read private profile fields via th
Overview
The Ultimate Member plugin for WordPress has an authorization bypass that allows unauthenticated users to read private profile fields via the wp_ajax_nopriv_um_get_members endpoint. This flaw exists in all versions up to 2.13.1 and can expose sensitive user data.
Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view privacy-restricted member profile field values — including fields explicitly configured as owner-only, members-only, or role-restricted — by querying the publicly accessible wp_ajax_nopriv_um_get_members endpoint. The nonce required by the endpoint ('um-frontend-nonce') is emitted to all unauthenticated visitors via wp_localize_script, meaning it provides no meaningful access control and any anonymous visitor can satisfy the endpoint's authentication requirements.
Impact
Confidentiality: private profile data may be disclosed to anyone. Integrity: no direct impact. Availability: not affected. Defenders: site owners, administrators, and security teams must be aware that any visitor can retrieve restricted fields.
Remediation
Update the Ultimate Member plugin to version 2.13.2 or later, which fixes the authorization check. If update not possible, disable the wp_ajax_nopriv_um_get_members endpoint via a custom plugin or .htaccess, or restrict access to the endpoint using a firewall rule. Ensure the nonce is not exposed to unauthenticated users.
Risk context
Severity is high with CVSS 7.5. No EPSS data available. The vulnerability allows data leakage without authentication, making it a high priority for sites using the plugin.
Affected products
- WordPress Ultimate Member plugin 2.13.1 and earlier
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —