Skip to content
Threat Feed
high advisory

Authorization Bypass in Ultimate Member Plugin for WordPress

An authorization bypass vulnerability in the Ultimate Member WordPress plugin allows unauthenticated attackers to exfiltrate private profile data via the wp_ajax_nopriv_um_get_members endpoint.

CVE search metadata

CVE search record: CVE-2026-93428. Severity: high. CVSS: 7.5. KEV: no. Product: Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin. Brief: Authorization Bypass in Ultimate Member Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ultimate-member-auth-bypass/

The Ultimate Member plugin for WordPress (versions 2.13.1 and earlier) contains a critical authorization bypass vulnerability related to the handling of user permissions. The plugin's wp_ajax_nopriv_um_get_members endpoint fails to properly verify user authorization before returning profile data. Specifically, the nonce mechanism ('um-frontend-nonce') used by this endpoint is exposed to all unauthenticated visitors through wp_localize_script. This flaw allows any anonymous user to supply the required nonce and query the endpoint to access sensitive member profile information. Attackers can leverage this to retrieve field values that were intended to be restricted to specific owners, members, or roles. This vulnerability poses a significant risk to user privacy on sites utilizing the plugin for member directories and content restriction.

Impact

Successful exploitation allows unauthenticated attackers to exfiltrate private user profile information from WordPress installations. This can lead to the unauthorized disclosure of sensitive PII or restricted membership data, impacting any site utilizing the plugin's profile visibility features.

Recommendation

Prioritize the update of the Ultimate Member plugin to a version addressing CVE-2026-93428. Monitor web server logs for high-frequency or unauthorized access attempts directed at the 'wp_ajax_nopriv_um_get_members' AJAX endpoint.


Immediate actions

Update Ultimate Member plugin to the latest available version

IT Operations 24h

Threat Hunt

Search web logs for unauthorized access to wp_ajax_nopriv_um_get_members

T1592 high medium confidence hunt now

Data: Web server access logs

Mitigations

Patch plugin versions <= 2.13.1

immediate IT Operations

CVE-2026-93428

Detection coverage 1

Detect CVE-2026-93428 Exploitation - Unauthorized Access to Member Profiles

high

Detects exploitation attempts against the wp_ajax_nopriv_um_get_members endpoint by monitoring for requests that target the member retrieval logic.

sigma tactics: exfiltration techniques: T1592 sources: webserver

Detection queries are available on the platform. Get full rules →