Stored XSS in Ultimate Member Plugin for WordPress
The Ultimate Member WordPress plugin (<= 2.13.1) contains a stored XSS vulnerability in the form_id parameter, allowing unauthenticated attackers to execute arbitrary scripts in the administrator dashboard.
CVE search metadata
CVE search record: CVE-2026-96270. Severity: high. CVSS: 7.2. KEV: no. Product: Ultimate Member (<= 2.13.1). Brief: Stored XSS in Ultimate Member Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96270/
The Ultimate Member WordPress plugin, version 2.13.1 and earlier, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. This vulnerability arises from improper input sanitization and output escaping of the 'form_id' parameter during user registration. An unauthenticated attacker can submit a registration request containing a malicious payload, which is then stored in the database within the user's metadata. The attack is triggered when a privileged administrator accesses the user management interface in the WordPress dashboard. When the administrator views the affected user record, the plugin insecurely inserts the stored payload into the DOM using the jQuery .html() function, leading to the execution of the injected script within the administrator's browser session.
Impact
Successful exploitation results in arbitrary script execution in the context of an administrator's browser. This allows attackers to perform administrative actions on behalf of the victim, such as creating new rogue accounts, changing site settings, or facilitating further exploitation of the WordPress environment. This vulnerability affects all installations using the specified versions of the Ultimate Member plugin.
Recommendation
Prioritized actions for detection and mitigation teams:
- Update the Ultimate Member plugin to a version beyond 2.13.1 to ensure input sanitization and proper output escaping are implemented.
- Implement a Web Application Firewall (WAF) rule to inspect and block registration requests containing malicious script characters or tags in the 'form_id' parameter.
- Monitor web server access logs for anomalous registration attempts targeting the plugin's registration endpoints.
Immediate actions
Deploy detection rule for registration endpoint anomalies
Mitigations
Upgrade Ultimate Member plugin to version 2.13.2 or later
CVE-2026-96270
Detection coverage 1
Detects CVE-2026-96270 Exploitation - Malicious Script Injection via Registration
highDetects XSS attempts against the Ultimate Member plugin by inspecting registration requests for common script injection patterns in the form_id parameter.
Detection queries are available on the platform. Get full rules →