CVE Database /
CVE-2026-7761
CVE · High
CVE-2026-7761 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-7761
|
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.0 |
Missing Authorization |
High
8.8
|
< 2.12.0
|
2.12.0 |
2026-06-23 |
—
|
CVE-2026-7761
The Ultimate Member plugin's handling of password reset links is compromised due to a series of interconnected errors. In versions up to 2.11.4, an MD5 hash fallback allows any post ID to be used as a member directory identifier. This oversight can be exploited by attackers with Contributor-level access or higher via XMLRPC requests containing specially crafted meta fields, ultimately leading to the disclosure of password reset links for all users in the affected directories.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings