Skip to content
Threat Feed
medium advisory

Stored XSS in Ultimate Member Plugin for WordPress

The Ultimate Member WordPress plugin (<= 2.13.1) contains a stored XSS vulnerability in the form_id parameter, allowing unauthenticated attackers to execute arbitrary scripts in the administrator dashboard.

CVE search metadata

CVE search record: CVE-2026-96270. Severity: high. CVSS: 7.2. KEV: no. Product: Ultimate Member (<= 2.13.1). Brief: Stored XSS in Ultimate Member Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96270/

The Ultimate Member WordPress plugin, version 2.13.1 and earlier, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. This vulnerability arises from improper input sanitization and output escaping of the 'form_id' parameter during user registration. An unauthenticated attacker can submit a registration request containing a malicious payload, which is then stored in the database within the user's metadata. The attack is triggered when a privileged administrator accesses the user management interface in the WordPress dashboard. When the administrator views the affected user record, the plugin insecurely inserts the stored payload into the DOM using the jQuery .html() function, leading to the execution of the injected script within the administrator's browser session.

Impact

Successful exploitation results in arbitrary script execution in the context of an administrator's browser. This allows attackers to perform administrative actions on behalf of the victim, such as creating new rogue accounts, changing site settings, or facilitating further exploitation of the WordPress environment. This vulnerability affects all installations using the specified versions of the Ultimate Member plugin.

Recommendation

Prioritized actions for detection and mitigation teams:

  • Update the Ultimate Member plugin to a version beyond 2.13.1 to ensure input sanitization and proper output escaping are implemented.
  • Implement a Web Application Firewall (WAF) rule to inspect and block registration requests containing malicious script characters or tags in the 'form_id' parameter.
  • Monitor web server access logs for anomalous registration attempts targeting the plugin's registration endpoints.

Immediate actions

Deploy detection rule for registration endpoint anomalies

Detection Engineering 24h

Mitigations

Upgrade Ultimate Member plugin to version 2.13.2 or later

immediate IT Operations

CVE-2026-96270

Detection coverage 1

Detects CVE-2026-96270 Exploitation - Malicious Script Injection via Registration

high

Detects XSS attempts against the Ultimate Member plugin by inspecting registration requests for common script injection patterns in the form_id parameter.

sigma tactics: initial_access techniques: T1189 sources: webserver

Detection queries are available on the platform. Get full rules →