Junglewise Threat Intelligence

CVE-2025-15064: Ultimate Member WordPress plugin Stored XSS in user description

CVE-2025-15064 · Severity: medium · CVSS 6.4 · Published 2026-04-04

Technologies: Ultimate Member. Vendors: Ultimate Member.

Executive brief

The Ultimate Member plugin for WordPress, which manages user profiles and memberships, contains a security flaw that allows logged-in users to inject malicious scripts into their profile descriptions. If the 'HTML support' setting is enabled, these scripts will execute in the browser of any visitor or administrator who views the affected profile. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Ultimate Member WordPress plugin due to insufficient input sanitization and output escaping of the user description field. Authenticated attackers with subscriber-level permissions or higher can inject arbitrary web scripts into their profile. These scripts execute in the context of any user viewing the profile page. The vulnerability is specifically exploitable when the 'HTML support for user description' setting is active. The issue was addressed in version 2.11.2 by deprecating HTML usage in user descriptions and refactoring form sanitization to use 'user_description' kses filters.

Affected products

  • ultimatemember Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.1

Timeline

  • 2025-12-30: other: Fix developed and version 2.11.2 prepared
  • 2026-02-04: patched: Patch merged into development branch
  • 2026-04-04: disclosed: Public advisory published

References

Related threats