Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19423— Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms

Quick assessment

Affected
Unknown Ultimate Member
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ultimate Member WordPress 插件 2.13.0 版本之前,当无法解析配置文件表单所允许的角色集合时,不会验证提交的角色选择,而是将提交值与站点已注册的角色名称进行比对,而非与表单自身的允许列表进行比对。这使得通过该插件(2.13.0 之前版本)自带表单进行注册的未认证用户,能够为自己赋予任意权限,从而获得相当于管理员的访问权限。

AI Predicted 9.8 Difficulty: Easy EPSS 0.15% · P4

Possible ATT&CK Techniques 1 AI

T1079

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Ultimate Member 2.6.7< 2.13.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19423

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms
Source: CVE Program / CVE List V5
Vulnerability Description
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant themselves arbitrary capabilities and reach administrator-equivalent access.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Ultimate Member 2.6.7 ~ 2.13.0 -

II. Public POCs for CVE-2026-19423

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19423

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19423 (1)

Same Patch Batch · Unknown · 2026-08-28 · 11 CVEs total

CVE-2026-79996 User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Sett
CVE-2026-77701 WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders
CVE-2026-79706 Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal
CVE-2026-79995 User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via
CVE-2026-79615 Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Dis
CVE-2026-19084 Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read
CVE-2026-14567 WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Direc
CVE-2026-14558 WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder
CVE-2026-12514 Shared Files < 1.7.70 - Unauthenticated Limited File Upload
CVE-2026-12513 Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal

IV. Related Vulnerabilities

V. Comments for CVE-2026-19423

No comments yet


Leave a comment