{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aultimate_memberultimate_member/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ultimate_member:ultimate_member:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96270"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ultimate Member (\u003c= 2.13.1)"],"_cs_severities":["medium"],"_cs_tags":["wordpress","xss","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Ultimate Member"],"content_html":"\u003cp\u003eThe Ultimate Member WordPress plugin, version 2.13.1 and earlier, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. This vulnerability arises from improper input sanitization and output escaping of the 'form_id' parameter during user registration. An unauthenticated attacker can submit a registration request containing a malicious payload, which is then stored in the database within the user's metadata. The attack is triggered when a privileged administrator accesses the user management interface in the WordPress dashboard. When the administrator views the affected user record, the plugin insecurely inserts the stored payload into the DOM using the jQuery .html() function, leading to the execution of the injected script within the administrator's browser session.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary script execution in the context of an administrator's browser. This allows attackers to perform administrative actions on behalf of the victim, such as creating new rogue accounts, changing site settings, or facilitating further exploitation of the WordPress environment. This vulnerability affects all installations using the specified versions of the Ultimate Member plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and mitigation teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Ultimate Member plugin to a version beyond 2.13.1 to ensure input sanitization and proper output escaping are implemented.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block registration requests containing malicious script characters or tags in the 'form_id' parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous registration attempts targeting the plugin's registration endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T04:53:19Z","date_published":"2026-10-03T04:53:19Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96270/","summary":"The Ultimate Member WordPress plugin (\u003c= 2.13.1) contains a stored XSS vulnerability in the form_id parameter, allowing unauthenticated attackers to execute arbitrary scripts in the administrator dashboard.","title":"Stored XSS in Ultimate Member Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96270/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ultimate_member:ultimate_member:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}