HomeSecurityUltimate Member vulnerability exposes private profile fields

Ultimate Member vulnerability exposes private profile fields

The vulnerability CVE-2026-93428 in the Ultimate Member plugin for WordPress allowed unregistered visitors to view private profile fields, bypassing restrictions set by administrators. Versions up to 2.13.1 are affected, and the vulnerability is rated 7.5/10, in the high risk category.

Ultimate Member: vulnerability in private profiles

According to the technical log for CVE-2026-93428, the vulnerability was in the way the plugin handled member list views. The related functionality could return fields that should normally only be visible to logged-in users or specific roles.

The Ultimate Member vulnerability and private fields

Ultimate Member is used for member accounts, profiles, and user directories on WordPress sites. Administrators can define which items are visible publicly and which are restricted to the account owner, members, or selected roles.

The vulnerability allowed an unlogged visitor to bypass these restrictions via the public AJAX endpoint wp_ajax_nopriv_um_get_members. With a suitable request, the function could reveal field values ​​that had been marked as private, without first checking that the requester had permission to see them.

Another issue was that the plugin provided anonymous visitors with a um-frontend-nonce, which did not act as a meaningful access control. Having a nonce can help verify requests, but it is not a substitute for authentication and permissions for private data.

The exact scope of the report depends on the fields used by each site and the member directory settings. The report covers profile information that administrators had chosen to restrict; it does not mean that all details of each account were automatically disclosed.

Access control to member profiles

The vulnerability was reported as CVE-2026-93428. The NVD entry carries a CVSS 3.1 score of 7.5, which is rated as high. This score is for technical risk and is not an indication that a website has been compromised.

See also: Ultimate Member: Critical vulnerability in WordPress plugin

Affected versions and the fix

According to the vulnerability description, all versions of Ultimate Member up to and including 2.13.1 are affected. The plugin has more than 200,000 active installations, according to its WordPress.org. The number indicates the potential scope of the issue, but does not mean that all of those installations are using the vulnerable version.

Version 2.14.0 includes the fix. In the Ultimate Member release history on WordPress.org, the September 29th entry explicitly states that CVE-2026-93428 was fixed and that privacy protections were improved when displaying profile fields.

Administrators should check the installed version of the add-on on each site that uses it and upgrade to 2.14.0 or later. This update is especially important for communities, membership sites, and directories that store content that is not intended for public display.

The report describes data exposure through the directory feature, not a confirmed breach of a specific site. However, the lack of a login requirement means that administrators should not consider private fields protected just because users do not have an account or are not listed on public pages.

See also: WordPress backdoor recreates itself after cleanup

For a first assessment, technicians can look in the logs for requests to admin-ajax.php with the um_get_members. Such records do not in themselves prove that private data was downloaded, but they help identify unusual activity around the member directory.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

After installing the fix, it is useful to check the privacy settings of the member list and test the visibility of fields from incognito browsing. Such a check confirms that fields intended for members or specific roles are not displayed to non-logged-in visitors.

Add-on update and profile protection

Instant upgrade and verification of rights

The SecNews technical team recommends that administrators install the update immediately, verify that the upgrade is complete, and review whether the field settings still meet the needs of the site. In case of delay, temporarily disabling public member lists limits exposure until the fix is ​​implemented.

See also: CSRF vulnerability in Elementor allows attack via a link

The Ultimate Member case is a reminder that visibility settings need server-level control, not just hiding elements on the page. Upgrading to version 2.14.0 or later and verifying view permissions are the key steps for administrators.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS