The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Thu, 26 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Ultimate Member
Ultimate Member registration
CPEs cpe:2.3:a:ultimate_member:registration:*:*:*:*:*:*:*:*
Vendors & Products Ultimate Member
Ultimate Member registration
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-03-13T09:35:14.538Z

Updated: 2024-08-02T20:26:37.987Z

Reserved: 2024-03-01T21:53:06.815Z

Link: CVE-2024-2123

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:38.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-13T10:15:08.373

Modified: 2024-11-21T09:09:04.737

Link: CVE-2024-2123

cve-icon Redhat

No data.