CVE-2026-12251
Received Received - Intake

Unauthenticated Privilege Escalation in Ultimate Member WordPress Plugin

Vulnerability report for CVE-2026-12251, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: WPScan

Description

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a role exists and a role-selection field is present on a published registration form.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ultimate_member ultimate_member to 2.12.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Ultimate Member WordPress plugin before version 2.12.1. It allows unauthenticated users to register with administrator-level capabilities by exploiting a flaw in the role selection field on registration forms. The plugin does not filter administrator roles from selectable options and has a disabled default safeguard against elevated accounts.

Detection Guidance

Check if the Ultimate Member plugin version is below 2.12.1 by inspecting the plugin files or WordPress admin panel. Look for registration forms with role-selection fields that allow administrator-level roles.

Impact Analysis

An attacker could exploit this to gain full administrative access to a WordPress site without authentication. This could lead to complete site takeover, data theft, or further attacks on the server. The impact is severe as it allows full control over the website and its contents.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating compliance requirements for GDPR, HIPAA, and other regulations. Unauthorized admin access may result in unauthorized data exposure, access controls violations, and failure to meet regulatory standards for data protection and access management.

Mitigation Strategies

Update the Ultimate Member plugin to version 2.12.1 or later immediately. If updating is not possible, disable the plugin or remove administrator-level roles from registration forms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12251. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart