critical · CVSS v3 8.8
CVE-2026-96451
Ultimate Member plugin for WordPress has a critical authorization bypass that allows attackers to elevate privileges. The flaw exists in ver
Overview
Ultimate Member plugin for WordPress has a critical authorization bypass that allows attackers to elevate privileges. The flaw exists in versions up to 2.13.1 and can be exploited by manipulating user-controlled keys. It enables unauthorized access to restricted functions and data.
Description
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Impact
Confidentiality, integrity, and availability of WordPress sites may be compromised. Attackers can gain elevated privileges, access or modify user data, site settings, and sensitive content. This threatens site owners, administrators, and end users.
Remediation
Update Ultimate Member to version 2.13.2 or later. If an update is not possible, disable the plugin or restrict access to the affected functionality. Monitor user accounts for suspicious activity and enforce least privilege.
Risk context
The vulnerability is rated critical with a CVSS v3 score of 8.8. No EPSS data is available, but the lack of a patch for versions up to 2.13.1 means immediate action is recommended.
Affected products
- Ultimate Member
- WordPress
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —