SECURITYHIGHCVE-2026-93428

CVE-2026-93428: Ultimate Member Plugin Missing Authorization Exposes Private Profile Fields

Ultimate Member ≤2.13.1 has a missing-authorization flaw letting unauthenticated attackers read privacy-restricted profile fields via directory AJAX endpoint.

Dylan H.

Security Team

October 3, 2026
7 min read
CVE-2026-93428: Ultimate Member Plugin Missing Authorization Exposes Private Profile Fields

Affected Products

  • Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership plugin for WordPress, versions ≤ 2.13.1

Executive Summary

A Missing Authorization vulnerability (CVE-2026-93428) has been disclosed in the Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership plugin for WordPress, affecting all versions up to and including 2.13.1. The flaw allows unauthenticated attackers to view privacy-restricted member profile field values — including fields explicitly configured as owner-only, members-only, or role-restricted — by querying the plugin's publicly reachable member-directory AJAX endpoint.

CVSS Score: 7.5 (High) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

The vulnerability was reserved on 2026-09-17 and published on 2026-10-03, with Wordfence as the assigning CNA. It is tracked under CWE-862 (Missing Authorization). There is no evidence of in-the-wild exploitation and no public proof-of-concept at the time of disclosure. A fix is available in Ultimate Member 2.14.0.

Note: This advisory covers CVE-2026-93428 (authorization bypass / private field disclosure) only. A separate, unrelated stored XSS issue in the same plugin version (via the form_id parameter) is tracked as CVE-2026-96270 and is documented in its own advisory.


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-93428
CVSS v3.1 Score7.5 (High)
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWECWE-862 — Missing Authorization
Affected ProductUltimate Member plugin for WordPress
Affected Versions≤ 2.13.1
Fixed Version2.14.0
Attack VectorNetwork (no authentication required)
Privileges RequiredNone
User InteractionNone
Assigning CNAWordfence
Date Reserved2026-09-17
Date Published2026-10-03
Known ExploitationNone reported (not in CISA KEV)

How It Works

Root Cause

Ultimate Member's member directory feature exposes an AJAX action, wp_ajax_nopriv_um_get_members, that is intentionally reachable by logged-out visitors so the public directory can render. The plugin gates that endpoint with a nonce check using um-frontend-nonce — but that nonce is generated and emitted to every visitor, authenticated or not, via wp_localize_script. Because the "secret" required to call the endpoint is handed out to anyone who loads a page, the nonce provides no meaningful access control: it proves nothing about who is making the request.

The plugin then fails to separately verify, server-side, whether the requesting user is actually authorized to see each profile field being returned. Fields administrators configured as "Only logged in members can view", "Only you can view", or role-restricted are intended to be hidden from the general public — but the directory query logic does not re-check that visibility setting against the actual (unauthenticated) requester before serializing the field value into the AJAX response.

Affected Code Paths

Analysis of the 2.13.1 codebase identified the vulnerable logic spanning several files:

  • class-ajax-common.php — registers and dispatches the um_get_members AJAX action, including the nopriv variant
  • class-member-directory.php — builds the member directory query and result set returned to the client
  • class-fields.php — defines per-field visibility/privacy rules that are not consistently re-validated at output time
  • um-short-functions.php — helper functions used when assembling field output
  • um-actions-profile.php — profile-rendering logic that shares the same field-privacy gap

Attack Path

1. Attacker identifies a public WordPress site running Ultimate Member ≤ 2.13.1
   with the Member Directory feature enabled
2. Attacker loads any public page to harvest the publicly-emitted
   um-frontend-nonce value (no login required)
3. Attacker sends a request to wp_ajax_nopriv_um_get_members with the
   harvested nonce
4. The plugin treats the request as authorized because the nonce check
   passes — it never verifies the requester's actual membership/role
5. The directory response includes field values the site owner marked
   as owner-only, members-only, or role-restricted
6. Attacker scripts repeated/paginated requests to enumerate restricted
   fields across the full member base

No account, session, or user interaction is required at any step — only outbound network access to the target site.


Impact Assessment

Impact AreaDescription
ConfidentialityHigh — private/restricted profile fields (e.g. contact details, employment info, location data) can be read by anyone
IntegrityNone — the vulnerability does not allow data modification
AvailabilityNone — no denial-of-service component
ScaleAttackers can automate pagination to enumerate restricted fields across the entire member directory, not just a single profile
Downstream RiskDisclosed contact/employment data enables targeted phishing, account-recovery attacks, harassment, or identity profiling
Compliance ExposureUnauthorized disclosure of personal data configured as "private" may trigger privacy/regulatory obligations depending on jurisdiction and data involved

Sites most exposed are public-facing WordPress membership, community, and directory sites that rely on Ultimate Member's privacy/visibility controls to shield sensitive profile fields from the general public.


Affected Versions

PluginAffected VersionsFixed Version
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership≤ 2.13.12.14.0

Recommendations

For Site Administrators

  1. Update immediately to Ultimate Member 2.14.0 or later:
# Via WP-CLI
wp plugin update ultimate-member
 
# Verify the installed version
wp plugin get ultimate-member --field=version

Or via the dashboard: Plugins → Installed Plugins → Ultimate Member → Update Now.

  1. If immediate patching isn't possible, mitigate exposure until you can update:

    • Temporarily disable the Member Directory feature in Ultimate Member settings
    • Restrict or block requests to the um_get_members AJAX action at the web server or WAF layer
    • Review which profile fields are marked private/restricted and consider removing highly sensitive fields from public-facing forms entirely until patched
  2. Audit for prior exposure: check web server and application logs for anonymous (nopriv) requests to wp_ajax_nopriv_um_get_members, especially repeated or paginated calls from a single source, which may indicate directory scraping occurred before the patch was applied.

For Security Teams

  1. Add detection rules for high-volume or scripted access patterns against WordPress admin-ajax.php with action=um_get_members.
  2. Correlate AJAX access logs with WAF/CDN logs to identify scraping behavior that predates remediation.
  3. If sensitive fields were exposed, treat it as a potential data-disclosure incident — assess whether notification obligations apply based on the data types involved and applicable privacy regulations.
  4. Track plugin inventory across managed WordPress fleets; Ultimate Member is widely deployed on membership and community sites, making this a worthwhile addition to routine vulnerability scanning.

For End Users / Members

  1. If you maintain a profile on a site using Ultimate Member, review which fields you have populated and consider minimizing sensitive data (phone numbers, addresses, employer details) in fields that should be private.
  2. Watch for an uptick in targeted phishing, impersonation, or unsolicited contact following disclosure of this vulnerability on sites you use.

Key Takeaways

  1. CVE-2026-93428 is a missing-authorization flaw (CWE-862) in the Ultimate Member WordPress plugin, rated 7.5 (High), affecting all versions ≤ 2.13.1.
  2. The root cause is a nonce (um-frontend-nonce) that is handed out to every visitor, authenticated or not — so it cannot function as an access-control check for the wp_ajax_nopriv_um_get_members endpoint.
  3. Exploitation requires no authentication, no privileges, and no user interaction — only network access to a vulnerable site.
  4. Impact is limited to confidentiality (disclosure of privacy-restricted profile fields) — there is no integrity or availability impact.
  5. The fix is available in Ultimate Member 2.14.0; administrators should update immediately and audit logs for prior scraping activity.
  6. This is a separate issue from CVE-2026-96270 (stored XSS via form_id), also affecting Ultimate Member ≤ 2.13.1 — both should be remediated by the same 2.14.0 update, but they are distinct vulnerabilities.

Sources