Critical Bugs in Ultimate Member WordPress Plugin Endanger 100K Sites

Critical Bugs in Ultimate Member WordPress Plugin Endanger 100K Sites article imageIs your WordPress site using the Ultimate Member plugin? If so, you should be aware that the plugin contains critical privilege escalation vulnerabilities. To avoid any issues, you should update the plugin to the latest available version, 2.1.12, which was released on October 29, 2020.

The plugin has been actively installed on more than 100,000 sites, which can be under attack if left unpatched.

The purpose of the Ultimate Member plugin is to enhance user registration and account control on WordPress sites. The plugin enables site owners to create custom roles and control the privileges of site members. The utility automatically creates three forms to function properly, consisting of user registration, login, and profile management.

Three critical privilege escalation vulnerabilities in Ultimate Member WordPress plugin

Wordfence researchers “discovered that the user registration form lacked some checks on submitted user data.” The lack of checks enabled attackers to supply arbitrary user meta keys during the registration process. To spare our readers the heavy technical details, this created a critical vulnerability making it possible for initially unauthenticated users to escalate their privileges to an administrator.

Admin access in the hands of cybercriminals can lead to many malicious activities, including taking the site offline or infecting it with malware. Not surprisingly, the CVSS score of this vulnerability, which has been dubbed “Unauthenticated Privilege Escalation via User Meta,” is 10.00, or critical.

The second plugin vulnerability in Ultimate Member also has the same CVSS rating of 10.00. Known as “Unauthenticated Privilege Escalation via User Roles,” the critical flaw is related to the previous one. “Due to the lack of filtering on the role parameter that could be supplied during the registration process, an attacker could supply the role parameter with a WordPress capability or any custom Ultimate Member role and effectively be granted those privileges,” Wordfence says.

The third vulnerability rated 9.9 in terms of severity, is called “Authenticated Privilege Escalation via Profile Update.” The flaw stems from a lack of capability checks on a profile update. The bug can be used by authenticated users to escalate their privileges with minimal difficulty.

Full technical disclosure of the Ultimate Member plugin flaws is available in the original report. We also urge you to read HowToHosting.Guide’s useful article on web security.

Researched and created by:
Krum Popov
Passionate web entrepreneur, has been crafting web projects since 2007. In 2020, he founded HTH.Guide — a visionary platform dedicated to streamlining the search for the perfect web hosting solution. Read more...
Technically reviewed by:
Metodi Ivanov
Seasoned web development expert with 8+ years of experience, including specialized knowledge in hosting environments. His expertise guarantees that the content meets the highest standards in accuracy and aligns seamlessly with hosting technologies. Read more...

Leave a Comment

Your email address will not be published. Required fields are marked *

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree
At HTH.Guide, we offer transparent web hosting reviews, ensuring independence from external influences. Our evaluations are unbiased as we apply strict and consistent standards to all reviews.
While we may earn affiliate commissions from some of the companies featured, these commissions do not compromise the integrity of our reviews or influence our rankings.
The affiliate earnings contribute to covering account acquisition, testing expenses, maintenance, and development of our website and internal systems.
Trust HTH.Guide for reliable hosting insights and sincerity.