PatchSiren cyber security CVE debrief
CVE-2026-93428 ultimatemember CVE debrief
The Ultimate Member plugin for WordPress has an authorization bypass vulnerability in versions up to 2.13.1. This allows unauthenticated attackers to view privacy-restricted member profile field values. The vulnerability is due to improper authorization verification in the wp_ajax_nopriv_um_get_members endpoint. The endpoint's publicly accessible nonce provides no meaningful access control. Defenders should assess exposure and implement compensating controls to prevent unauthorized access to sensitive member profile information.
- Vendor
- ultimatemember
- Product
- Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for WordPress installations with the Ultimate Member plugin should assess exposure and implement compensating controls to prevent unauthorized access to sensitive member profile information.
Why it matters
The Ultimate Member plugin vulnerability allows unauthorized access to member profile field values, potentially leading to data exposure. Defenders should verify exposure, implement compensating controls, and prioritize patching or workarounds.
- Potential unauthorized access to sensitive member profile information
- Possible data exposure due to improper authorization verification
- Need for compensating controls to restrict access to sensitive member profile fields
- Verification of exposure and implementation of patches or workarounds is required
Technical summary
The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to improper verification of user authorization. This allows unauthenticated attackers to view privacy-restricted member profile field values by querying the publicly accessible wp_ajax_nopriv_um_get_members endpoint. The nonce 'um-frontend-nonce' is publicly accessible and does not provide meaningful access control. The vulnerability is due to inadequate authorization checks in the plugin's code. Defenders should prioritize verifying exposure and implementing compensating controls to restrict access to sensitive member profile information.
Defensive priority
Defenders should prioritize verifying exposure and implementing compensating controls, as the vulnerability allows unauthorized access to sensitive member profile information.
Recommended defensive actions
- Verify exposure by checking if the Ultimate Member plugin version is 2.13.1 or earlier
- Implement compensating controls, such as restricting access to sensitive member profile fields
- Monitor for suspicious activity on the wp_ajax_nopriv_um_get_members endpoint
- Consider upgrading to a patched version of the Ultimate Member plugin
- Review and update access controls for member profile fields
- Conduct regular security audits to identify potential vulnerabilities
- Implement additional logging and monitoring to detect potential exploitation attempts
Evidence notes
The vulnerability is due to improper authorization verification in the Ultimate Member plugin, specifically in the wp_ajax_nopriv_um_get_members endpoint. The nonce 'um-frontend-nonce' is publicly accessible and does not provide meaningful access control.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93428 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93428
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93428 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93428
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ultimatemember/ultimatemember/releases/tag/2.14.0
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.13.1/includes/core/class-ajax-common.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.13.1/includes/core/class-fields.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.13.1/includes/core/class-member-directory.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.13.1/includes/core/um-actions-profile.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.13.1/includes/um-short-functions.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.