An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to any role (e.g., Administrator) during a profile update, and effectively escalate their privileges.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HUltimatemember Ultimate Member
APPUltimatemember< 2.1.12
Related vulnerabilities
SQL Injection w pluginie Ultimate Member dla WordPress (CVE-2024-1071)
Ultimate Member WordPress — tworzenie kont administratora przez gości
Privilege escalation bez uwierzytelnienia w pluginie Ultimate Member dla WordPress
Ultimate Member Plugin – Nieuwierzytelniony Privilege Escalation przez User Meta
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Pl...