rootpwn

high · CVSS v3 7.5

CVE-2026-93428

The Ultimate Member plugin for WordPress has an authorization bypass that allows unauthenticated users to read private profile fields via th

Overview

The Ultimate Member plugin for WordPress has an authorization bypass that allows unauthenticated users to read private profile fields via the wp_ajax_nopriv_um_get_members endpoint. This flaw exists in all versions up to 2.13.1 and can expose sensitive user data.

Description

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view privacy-restricted member profile field values — including fields explicitly configured as owner-only, members-only, or role-restricted — by querying the publicly accessible wp_ajax_nopriv_um_get_members endpoint. The nonce required by the endpoint ('um-frontend-nonce') is emitted to all unauthenticated visitors via wp_localize_script, meaning it provides no meaningful access control and any anonymous visitor can satisfy the endpoint's authentication requirements.

Impact

Confidentiality: private profile data may be disclosed to anyone. Integrity: no direct impact. Availability: not affected. Defenders: site owners, administrators, and security teams must be aware that any visitor can retrieve restricted fields.

Remediation

Update the Ultimate Member plugin to version 2.13.2 or later, which fixes the authorization check. If update not possible, disable the wp_ajax_nopriv_um_get_members endpoint via a custom plugin or .htaccess, or restrict access to the endpoint using a firewall rule. Ensure the nonce is not exposed to unauthenticated users.

Risk context

Severity is high with CVSS 7.5. No EPSS data available. The vulnerability allows data leakage without authentication, making it a high priority for sites using the plugin.

Affected products

  • WordPress Ultimate Member plugin 2.13.1 and earlier

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
—
EPSS
—

WordPress plugin authorization-bypass privacy data-leak wp_ajax nonce user-profile

← All CVEs