Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-96451 — WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability | Kitploit
Tools/GitHubGitHub/nxploited/cve-2026-96451
Privilege EscalationVulnerability ScannersPassword AttacksVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubnxploited/cve-2026-96451

CVE-2026-96451

WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

View Repository
412h 53m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-96451

WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

🔥 CVE-2026-96451

Ultimate Member <= 2.13.1 — Privilege Escalation / Account Takeover

📌 Official record: CVE-2026-96451


📋 Description

From CVE.org:

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation. This issue affects Ultimate Member: from n/a through 2.13.1.

FieldValue
🆔 CVECVE-2026-96451
🏷️ CWECWE-639 — Authorization Bypass Through User-Controlled Key
📊 CVSS 3.18.8 HIGH AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
🏢 AssignerPatchstack
⚠️ AffectedUltimate Member through 2.13.1
✅ Fixed2.14.0

A logged-in subscriber can change another user's email (usually the administrator). WordPress then accepts a password reset for that new mailbox.


🧠 How it works

  1. Ultimate Member checks a download nonce, then calls um_fetch_user($user_id) and switches the global user to the ID in the URL.
  2. If the file field does not exist, download_routing() returns without um_reset_user().
  3. The same request also carries account-form fields (_um_account=1, user_email=...).
  4. account_submit() reads um_user('ID') — now the victim — and writes the new email.

The download nonce is wp_create_nonce($user_id . $form_id . 'um-download-nonce'). It is tied to that user ID. It cannot be invented. The script copies it from a visible /um-download/{form}/{field}/{user}/{nonce}/ link.

A custom file or image field must be shown on the profile. Built-in profile/cover photos do not produce this link.


⚙️ Requirements

pip install requests rich
  • Python 3.9+
  • Target list: one URL per line

🚀 Usage

Registration, login, nonce collection, exploit, and reset check are automatic. You do not create accounts by hand and you do not pass a subscriber password for a mass scan.

Mass scan

python CVE-2026-96451.py -l targets.txt -t 80 --email "[email protected]" -o um_takeover.txt

What this command does on every host:

  1. 🔎 Detect Ultimate Member
  2. 📝 Register a subscriber on the public UM form
  3. 🔑 Sign in and open /account/
  4. 📂 Find a visible /um-download/ nonce (prefers user ID 1, then any member with a file)
  5. 💥 POST the identity-confusion request and set the account email to --email
  6. 📬 Probe wp-login.php?action=lostpassword (WordPress does not need a nonce here)
  7. 💾 Write the stage to um_takeover.txt

--email is the mailbox placed on the target account so you can receive the reset. The script does not open the inbox or set a new password. That last step is manual.

Single host

python CVE-2026-96451.py -u "https://example.com" --email "[email protected]"

Optional flags

FlagPurposeDefault
-l / --listFile of targets—
-u / --urlOne target—
-t / --threadsWorkers10
-o / --outputResult fileum_takeover.txt
--emailMailbox written onto the victimauto-generated
--target-idPreferred user ID1
--user / --passwordUse an existing subscriber instead of registeringoff
-v / --verbosePrint every stageoff

On a slow RDP box, 80–150 threads is enough. A list scan gives each host about 22 seconds.


📟 Status line

[5400/11965]  RST:0  CHG:0  UM:4463  REG:589  rf:3874 lf:0 na:141 nd:448 nc:0 no:937
CodeMeaning
RST / CHGEmail changed and/or reset accepted — check the inbox
UMUltimate Member detected
REGAuto-registration created a session
rfNo public form, CAPTCHA, approval, or email activation
lfRegistered but login failed
naAccount page / nonce missing
ndNo visible download nonce (no custom file field)
ncExploit sent, change not confirmed
noNot Ultimate Member

REG_FAIL on many hosts is normal. The chain only continues where registration creates a session and a download link is visible.

When RST or CHG appears:

  1. Open the mailbox passed to --email
  2. Open the WordPress reset message
  3. Set a password
  4. Sign in at /wp-login.php or /wp-admin/

⚖️ Disclaimer

This project is for authorized security research only — systems you own or have written permission to test.

Unauthorized access to computer systems is illegal. The author accepts no liability for misuse, damage, or any outcome of this software. You are solely responsible for how it is used and for every target you scan.

By: Nxploited ( Khaled Alenazi )

Download Tool