The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Project Subscriptions

Vendors Products
Ultimate Member Subscribe
Registration Subscribe
Ultimatemember Subscribe
Ultimate Member Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 08 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Ultimatemember
Ultimatemember ultimate Member
CPEs cpe:2.3:a:ultimatemember:ultimate_member:*:*:*:*:*:wordpress:*:*
Vendors & Products Ultimatemember
Ultimatemember ultimate Member

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Title Ultimate Member <= 2.8.3 - Unauthenticated Stored Cross-Site Scripting
Weaknesses CWE-79

Thu, 26 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Ultimate Member
Ultimate Member registration
CPEs cpe:2.3:a:ultimate_member:registration:*:*:*:*:*:*:*:*
Vendors & Products Ultimate Member
Ultimate Member registration
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:21:38.782Z

Reserved: 2024-03-01T21:53:06.815Z

Link: CVE-2024-2123

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:38.960Z

cve-icon NVD

Status : Modified

Published: 2024-03-13T10:15:08.373

Modified: 2026-04-08T19:21:00.097

Link: CVE-2024-2123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses