These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Ultimate Member plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the 'form_id' parameter in versions up to 2.13.1. This allows unauthenticated attackers to inject web scripts that execute when an administrator accesses the affected user record. The vulnerability is tracked in CVE-2026-96270 and was reported by [email protected]. The injected payload is stored in the regist [truncated]
The Ultimate Member plugin for WordPress has an authorization bypass vulnerability in versions up to 2.13.1, allowing unauthenticated attackers to view privacy-restricted member profile field values. This vulnerability is due to improper authorization checks, potentially leading to data exposure. Defenders should assess exposure and prioritize remediation, focusing on verifying installed plugin versions a [truncated]
The Ultimate Member plugin for WordPress has a Stored Cross-Site Scripting vulnerability via Textarea Profile Field with HTML Support. Authenticated attackers with subscriber-level access can inject web scripts that execute when a user accesses an injected page. This vulnerability exists due to insufficient input sanitization and output escaping, allowing attackers to smuggle onfocus and autofocus attribu [truncated]
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This vulnerability allows unauthenticated a [truncated]
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber level access and above, [truncated]