PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15064 ultimatemember CVE debrief

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is only exploitable when 'HTML support for user description' is enabled in Ultimate Member settings.

Vendor
ultimatemember
Product
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-04
Original CVE updated
2026-07-24
Advisory published
2026-04-04
Advisory updated
2026-07-24

Who should care

Users of the Ultimate Member plugin for WordPress, particularly those with subscriber level access and above, should be aware of this vulnerability and take steps to mitigate it. Website administrators and security teams should prioritize patching and monitoring for potential exploitation.

Technical summary

The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the user description field. An authenticated attacker with subscriber level access and above can inject arbitrary web scripts, which will execute when a user accesses an injected page. The vulnerability exists in all versions up to and including 2.11.1 and is exploitable only when 'HTML support for user description' is enabled in Ultimate Member settings.

Defensive priority

Medium priority should be given to patching this vulnerability, as it requires authenticated access and specific settings to be exploitable.

Recommended defensive actions

  • Patch the Ultimate Member plugin to version 2.11.2 or later
  • Verify that 'HTML support for user description' is not enabled in Ultimate Member settings unless necessary
  • Monitor for suspicious user description changes and injected scripts
  • Implement additional security measures for user input validation and output encoding
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-04-04T08:16:05.543Z and last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Deferred. The vulnerability was reported by [email protected]. Evidence is limited to public CVE and NVD information. Defenders should verify vulnerability scope, affected deployments, and patch status with the vendor and monitor for suspicious user description changes and injected scripts.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-04T08:16:05.543Z and has not been modified since then. The NVD entry is currently Deferred.