Authorization Bypass in Ultimate Member Plugin for WordPress
An authorization bypass vulnerability in the Ultimate Member WordPress plugin allows unauthenticated attackers to exfiltrate private profile data via the wp_ajax_nopriv_um_get_members endpoint.
CVE search metadata
CVE search record: CVE-2026-93428. Severity: high. CVSS: 7.5. KEV: no. Product: Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin. Brief: Authorization Bypass in Ultimate Member Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ultimate-member-auth-bypass/
The Ultimate Member plugin for WordPress (versions 2.13.1 and earlier) contains a critical authorization bypass vulnerability related to the handling of user permissions. The plugin's wp_ajax_nopriv_um_get_members endpoint fails to properly verify user authorization before returning profile data. Specifically, the nonce mechanism ('um-frontend-nonce') used by this endpoint is exposed to all unauthenticated visitors through wp_localize_script. This flaw allows any anonymous user to supply the required nonce and query the endpoint to access sensitive member profile information. Attackers can leverage this to retrieve field values that were intended to be restricted to specific owners, members, or roles. This vulnerability poses a significant risk to user privacy on sites utilizing the plugin for member directories and content restriction.
Impact
Successful exploitation allows unauthenticated attackers to exfiltrate private user profile information from WordPress installations. This can lead to the unauthorized disclosure of sensitive PII or restricted membership data, impacting any site utilizing the plugin's profile visibility features.
Recommendation
Prioritize the update of the Ultimate Member plugin to a version addressing CVE-2026-93428. Monitor web server logs for high-frequency or unauthorized access attempts directed at the 'wp_ajax_nopriv_um_get_members' AJAX endpoint.
Immediate actions
Update Ultimate Member plugin to the latest available version
Threat Hunt
Search web logs for unauthorized access to wp_ajax_nopriv_um_get_members
Data: Web server access logs
Mitigations
Patch plugin versions <= 2.13.1
CVE-2026-93428
Detection coverage 1
Detect CVE-2026-93428 Exploitation - Unauthorized Access to Member Profiles
highDetects exploitation attempts against the wp_ajax_nopriv_um_get_members endpoint by monitoring for requests that target the member retrieval logic.
Detection queries are available on the platform. Get full rules →