CVE Database /
CVE-2026-12251
CVE
CVE-2026-12251 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12251
|
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.1 |
Improper Privilege Management |
Unknown
|
< 2.12.1
|
2.12.1 |
2026-07-31 |
—
|
CVE-2026-12251
Prior versions of the Ultimate Member plugin for WordPress, specifically those below 2.12.1, are susceptible to unauthorized account elevation due to an oversight in capability filtering during user registration. The plugin's default configuration disables its built-in safeguard against excessive privileges, allowing unverified users to register with a role that grants administrative access if such a role exists and is presented on the registration form.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings