CVE-2026-19251
Received Received - Intake

Unauthenticated Comment Content Exposure in Ultimate Member

Vulnerability report for CVE-2026-19251, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting moderation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ultimate_member ultimate_member to 2.13.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Ultimate Member WordPress plugin versions before 2.13.0. It allows unauthenticated users to view unapproved comments on user profiles because the plugin fails to check if comments are approved or if the profile is private before showing profile activity. This exposes moderation-pending comment content to unauthorized visitors.

Detection Guidance

Check if the Ultimate Member plugin version is below 2.13.0 by inspecting the plugin files or WordPress admin panel. Look for unapproved comments on user profiles that may be visible to unauthenticated users.

Impact Analysis

This vulnerability can lead to unauthorized access to sensitive information. If you use the affected plugin version, unauthenticated users could read comments that are still awaiting moderation, potentially exposing private or confidential data before it is approved for public view.

Compliance Impact

This vulnerability may lead to non-compliance with GDPR and HIPAA due to unauthorized exposure of sensitive user data. Unapproved comments could contain personal or health information, violating data protection requirements for confidentiality and access controls.

Mitigation Strategies

Update the Ultimate Member plugin to version 2.13.0 or later immediately. If updating is not possible, consider temporarily disabling the plugin until the update can be applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19251. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart