Junglewise Threat Intelligence

CVE-2026-19423: Ultimate Member WordPress plugin privilege escalation via role field

CVE-2026-19423 · Severity: high · CVSS 8.1 · Published 2026-08-28

Technologies: Ultimate Member. Vendors: Ultimate Member.

Executive brief

The Ultimate Member WordPress plugin is used to manage user registration and profile forms on WordPress sites. The plugin fails to properly validate user-submitted role selections during registration, allowing unauthenticated attackers to register and automatically grant themselves administrator-level access. This could allow attackers to take complete control of affected WordPress installations.

Technical details

The vulnerability is a privilege escalation flaw in the Ultimate Member WordPress plugin versions 2.6.7 through 2.12.1. When a profile form cannot resolve the list of permitted roles, the plugin validates submitted role values against the site's global registered roles instead of the form's own allow-list, enabling an attacker to submit an arbitrary role during unauthenticated registration. An attacker can craft a registration request specifying an administrative role, which the plugin accepts without proper validation, granting them administrator-equivalent capabilities. The issue is fixed in version 2.13.0.

Affected products

  • Ultimate Member Ultimate Member 2.6.7 through 2.12.1

Timeline

  • 2026-08-26: disclosed
  • 2026-08-28: patched: Fixed in version 2.13.0

References

Related threats