<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ultimate-member--user-profile-registration-login-member-directory-content-restriction--membership-plugin/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 04:53:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ultimate-member--user-profile-registration-login-member-directory-content-restriction--membership-plugin/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Ultimate Member Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-ultimate-member-auth-bypass/</link><pubDate>Sat, 03 Oct 2026 04:53:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ultimate-member-auth-bypass/</guid><description>An authorization bypass vulnerability in the Ultimate Member WordPress plugin allows unauthenticated attackers to exfiltrate private profile data via the wp_ajax_nopriv_um_get_members endpoint.</description><content:encoded><![CDATA[<p>The Ultimate Member plugin for WordPress (versions 2.13.1 and earlier) contains a critical authorization bypass vulnerability related to the handling of user permissions. The plugin's wp_ajax_nopriv_um_get_members endpoint fails to properly verify user authorization before returning profile data. Specifically, the nonce mechanism ('um-frontend-nonce') used by this endpoint is exposed to all unauthenticated visitors through wp_localize_script. This flaw allows any anonymous user to supply the required nonce and query the endpoint to access sensitive member profile information. Attackers can leverage this to retrieve field values that were intended to be restricted to specific owners, members, or roles. This vulnerability poses a significant risk to user privacy on sites utilizing the plugin for member directories and content restriction.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to exfiltrate private user profile information from WordPress installations. This can lead to the unauthorized disclosure of sensitive PII or restricted membership data, impacting any site utilizing the plugin's profile visibility features.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the update of the Ultimate Member plugin to a version addressing CVE-2026-93428. Monitor web server logs for high-frequency or unauthorized access attempts directed at the 'wp_ajax_nopriv_um_get_members' AJAX endpoint.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>