WordPress website owners using the Ultimate Member plugin should immediately apply the latest update , as their websites are at risk of a series of bugs that hackers can exploit and take control of.

Ultimate Member is a plugin with over 100,000 active installations, designed to make the task of profile management and membership easier.
The plugin provides support for creating websites that allow for easy registration and the creation of online communities with customized privileges for various user roles.
According to a study by Wordfence 's Threat Intelligence team , analyst Chloe Chamberland said that the three security flaws revealed could allow attackers to escalate their privileges to gain administrator rights and take full control of any WordPress site.
The bugs were fixed with the release of Ultimate Member 2.1.12 on October 29, about three days after they were discovered.

One of the bugs was rated “very critical,” as it “allows initially unauthorized users to easily escalate their privileges to those of an administrator.”
“Once an attacker has administrator access to a WordPress site, they have effectively taken over the entire site and can perform any action, from taking the site offline to further infecting the site with malware,” Chamberland explained.
Two of the bugs received a maximum CVSS score of 10/10, as they are unauthorized privilege escalation bugs via “meta-user” (granting administrator access during sign-up) and user roles (administrator role selected during sign-up).
The third was rated 9.8/10, as it requires wp-admin access to the profile.php , but is still considered critical, as it allows any authenticated attacker to gain admin privileges with very little effort.
Ultimate Member users are urged to update the plugin to version 2.1.12 as soon as possible to prevent attacks.
