PatchSiren

Ultimate Member CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Ultimate Member CVE published 2026-10-03

CVE-2026-96451

CVE-2026-96451 is an Authorization Bypass Through User-Controlled Key vulnerability in the Ultimate Member plugin for WordPress, allowing for Privilege Escalation. This issue affects Ultimate Member versions from n/a through 2.13.1. The vulnerability has a high severity score and defenders should assess potential exposure and impact. This includes administrators, security teams, and developers who manage [truncated]