{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ultimate-member--user-profile-registration-login-member-directory-content-restriction--membership-plugin/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ultimatemember:ultimate_member:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93428"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction \u0026 Membership Plugin"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Ultimate Member"],"content_html":"\u003cp\u003eThe Ultimate Member plugin for WordPress (versions 2.13.1 and earlier) contains a critical authorization bypass vulnerability related to the handling of user permissions. The plugin's wp_ajax_nopriv_um_get_members endpoint fails to properly verify user authorization before returning profile data. Specifically, the nonce mechanism ('um-frontend-nonce') used by this endpoint is exposed to all unauthenticated visitors through wp_localize_script. This flaw allows any anonymous user to supply the required nonce and query the endpoint to access sensitive member profile information. Attackers can leverage this to retrieve field values that were intended to be restricted to specific owners, members, or roles. This vulnerability poses a significant risk to user privacy on sites utilizing the plugin for member directories and content restriction.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to exfiltrate private user profile information from WordPress installations. This can lead to the unauthorized disclosure of sensitive PII or restricted membership data, impacting any site utilizing the plugin's profile visibility features.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of the Ultimate Member plugin to a version addressing CVE-2026-93428. Monitor web server logs for high-frequency or unauthorized access attempts directed at the 'wp_ajax_nopriv_um_get_members' AJAX endpoint.\u003c/p\u003e\n","date_modified":"2026-10-03T04:53:10Z","date_published":"2026-10-03T04:53:10Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ultimate-member-auth-bypass/","summary":"An authorization bypass vulnerability in the Ultimate Member WordPress plugin allows unauthenticated attackers to exfiltrate private profile data via the wp_ajax_nopriv_um_get_members endpoint.","title":"Authorization Bypass in Ultimate Member Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-ultimate-member-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction \u0026 Membership Plugin","version":"https://jsonfeed.org/version/1.1"}