CVE · High

CVE-2026-7761 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-7761 Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.0 Missing Authorization High 8.8 < 2.12.0 2.12.0 2026-06-23

CVE-2026-7761

The Ultimate Member plugin's handling of password reset links is compromised due to a series of interconnected errors. In versions up to 2.11.4, an MD5 hash fallback allows any post ID to be used as a member directory identifier. This oversight can be exploited by attackers with Contributor-level access or higher via XMLRPC requests containing specially crafted meta fields, ultimately leading to the disclosure of password reset links for all users in the affected directories.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.