rootpwn

critical · CVSS v3 8.8

CVE-2026-96451

Ultimate Member plugin for WordPress has a critical authorization bypass that allows attackers to elevate privileges. The flaw exists in ver

Overview

Ultimate Member plugin for WordPress has a critical authorization bypass that allows attackers to elevate privileges. The flaw exists in versions up to 2.13.1 and can be exploited by manipulating user-controlled keys. It enables unauthorized access to restricted functions and data.

Description

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

Impact

Confidentiality, integrity, and availability of WordPress sites may be compromised. Attackers can gain elevated privileges, access or modify user data, site settings, and sensitive content. This threatens site owners, administrators, and end users.

Remediation

Update Ultimate Member to version 2.13.2 or later. If an update is not possible, disable the plugin or restrict access to the affected functionality. Monitor user accounts for suspicious activity and enforce least privilege.

Risk context

The vulnerability is rated critical with a CVSS v3 score of 8.8. No EPSS data is available, but the lack of a patch for versions up to 2.13.1 means immediate action is recommended.

Affected products

  • Ultimate Member
  • WordPress

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
—
EPSS
—

wordpress plugin authorization-bypass privilege-escalation critical CVE-2026-96451

← All CVEs