Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 28 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ultimatemember
Ultimatemember ultimate Member Wordpress Wordpress wordpress |
|
| Weaknesses | CWE-269 CWE-285 |
|
| Vendors & Products |
Ultimatemember
Ultimatemember ultimate Member Wordpress Wordpress wordpress |
Fri, 28 Aug 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant themselves arbitrary capabilities and reach administrator-equivalent access. | |
| Title | Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-28T06:00:16.618Z
Reserved: 2026-08-10T11:01:48.677Z
Link: CVE-2026-19423
Updated: 2026-08-28T12:57:57.813Z
Status : Received
Published: 2026-08-28T08:16:40.610
Modified: 2026-08-28T08:16:40.610
Link: CVE-2026-19423
No data.
OpenCVE Enrichment
Updated: 2026-08-28T09:00:10Z