Executive brief
The Ultimate Member WordPress plugin is used to manage user registration and profile forms on WordPress sites. The plugin fails to properly validate user-submitted role selections during registration, allowing unauthenticated attackers to register and automatically grant themselves administrator-level access. This could allow attackers to take complete control of affected WordPress installations.
Technical details
The vulnerability is a privilege escalation flaw in the Ultimate Member WordPress plugin versions 2.6.7 through 2.12.1. When a profile form cannot resolve the list of permitted roles, the plugin validates submitted role values against the site's global registered roles instead of the form's own allow-list, enabling an attacker to submit an arbitrary role during unauthenticated registration. An attacker can craft a registration request specifying an administrative role, which the plugin accepts without proper validation, granting them administrator-equivalent capabilities. The issue is fixed in version 2.13.0.
Affected products
- Ultimate Member Ultimate Member 2.6.7 through 2.12.1
Timeline
- 2026-08-26: disclosed
- 2026-08-28: patched: Fixed in version 2.13.0