Executive Summary
A Missing Authorization vulnerability (CVE-2026-93428) has been disclosed in the Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership plugin for WordPress, affecting all versions up to and including 2.13.1. The flaw allows unauthenticated attackers to view privacy-restricted member profile field values — including fields explicitly configured as owner-only, members-only, or role-restricted — by querying the plugin's publicly reachable member-directory AJAX endpoint.
CVSS Score: 7.5 (High) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The vulnerability was reserved on 2026-09-17 and published on 2026-10-03, with Wordfence as the assigning CNA. It is tracked under CWE-862 (Missing Authorization). There is no evidence of in-the-wild exploitation and no public proof-of-concept at the time of disclosure. A fix is available in Ultimate Member 2.14.0.
Note: This advisory covers CVE-2026-93428 (authorization bypass / private field disclosure) only. A separate, unrelated stored XSS issue in the same plugin version (via the
form_idparameter) is tracked as CVE-2026-96270 and is documented in its own advisory.
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-93428 |
| CVSS v3.1 Score | 7.5 (High) |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CWE | CWE-862 — Missing Authorization |
| Affected Product | Ultimate Member plugin for WordPress |
| Affected Versions | ≤ 2.13.1 |
| Fixed Version | 2.14.0 |
| Attack Vector | Network (no authentication required) |
| Privileges Required | None |
| User Interaction | None |
| Assigning CNA | Wordfence |
| Date Reserved | 2026-09-17 |
| Date Published | 2026-10-03 |
| Known Exploitation | None reported (not in CISA KEV) |
How It Works
Root Cause
Ultimate Member's member directory feature exposes an AJAX action, wp_ajax_nopriv_um_get_members, that is intentionally reachable by logged-out visitors so the public directory can render. The plugin gates that endpoint with a nonce check using um-frontend-nonce — but that nonce is generated and emitted to every visitor, authenticated or not, via wp_localize_script. Because the "secret" required to call the endpoint is handed out to anyone who loads a page, the nonce provides no meaningful access control: it proves nothing about who is making the request.
The plugin then fails to separately verify, server-side, whether the requesting user is actually authorized to see each profile field being returned. Fields administrators configured as "Only logged in members can view", "Only you can view", or role-restricted are intended to be hidden from the general public — but the directory query logic does not re-check that visibility setting against the actual (unauthenticated) requester before serializing the field value into the AJAX response.
Affected Code Paths
Analysis of the 2.13.1 codebase identified the vulnerable logic spanning several files:
class-ajax-common.php— registers and dispatches theum_get_membersAJAX action, including thenoprivvariantclass-member-directory.php— builds the member directory query and result set returned to the clientclass-fields.php— defines per-field visibility/privacy rules that are not consistently re-validated at output timeum-short-functions.php— helper functions used when assembling field outputum-actions-profile.php— profile-rendering logic that shares the same field-privacy gap
Attack Path
1. Attacker identifies a public WordPress site running Ultimate Member ≤ 2.13.1
with the Member Directory feature enabled
2. Attacker loads any public page to harvest the publicly-emitted
um-frontend-nonce value (no login required)
3. Attacker sends a request to wp_ajax_nopriv_um_get_members with the
harvested nonce
4. The plugin treats the request as authorized because the nonce check
passes — it never verifies the requester's actual membership/role
5. The directory response includes field values the site owner marked
as owner-only, members-only, or role-restricted
6. Attacker scripts repeated/paginated requests to enumerate restricted
fields across the full member baseNo account, session, or user interaction is required at any step — only outbound network access to the target site.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | High — private/restricted profile fields (e.g. contact details, employment info, location data) can be read by anyone |
| Integrity | None — the vulnerability does not allow data modification |
| Availability | None — no denial-of-service component |
| Scale | Attackers can automate pagination to enumerate restricted fields across the entire member directory, not just a single profile |
| Downstream Risk | Disclosed contact/employment data enables targeted phishing, account-recovery attacks, harassment, or identity profiling |
| Compliance Exposure | Unauthorized disclosure of personal data configured as "private" may trigger privacy/regulatory obligations depending on jurisdiction and data involved |
Sites most exposed are public-facing WordPress membership, community, and directory sites that rely on Ultimate Member's privacy/visibility controls to shield sensitive profile fields from the general public.
Affected Versions
| Plugin | Affected Versions | Fixed Version |
|---|---|---|
| Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership | ≤ 2.13.1 | 2.14.0 |
Recommendations
For Site Administrators
- Update immediately to Ultimate Member 2.14.0 or later:
# Via WP-CLI
wp plugin update ultimate-member
# Verify the installed version
wp plugin get ultimate-member --field=versionOr via the dashboard: Plugins → Installed Plugins → Ultimate Member → Update Now.
-
If immediate patching isn't possible, mitigate exposure until you can update:
- Temporarily disable the Member Directory feature in Ultimate Member settings
- Restrict or block requests to the
um_get_membersAJAX action at the web server or WAF layer - Review which profile fields are marked private/restricted and consider removing highly sensitive fields from public-facing forms entirely until patched
-
Audit for prior exposure: check web server and application logs for anonymous (
nopriv) requests towp_ajax_nopriv_um_get_members, especially repeated or paginated calls from a single source, which may indicate directory scraping occurred before the patch was applied.
For Security Teams
- Add detection rules for high-volume or scripted access patterns against WordPress
admin-ajax.phpwithaction=um_get_members. - Correlate AJAX access logs with WAF/CDN logs to identify scraping behavior that predates remediation.
- If sensitive fields were exposed, treat it as a potential data-disclosure incident — assess whether notification obligations apply based on the data types involved and applicable privacy regulations.
- Track plugin inventory across managed WordPress fleets; Ultimate Member is widely deployed on membership and community sites, making this a worthwhile addition to routine vulnerability scanning.
For End Users / Members
- If you maintain a profile on a site using Ultimate Member, review which fields you have populated and consider minimizing sensitive data (phone numbers, addresses, employer details) in fields that should be private.
- Watch for an uptick in targeted phishing, impersonation, or unsolicited contact following disclosure of this vulnerability on sites you use.
Key Takeaways
- CVE-2026-93428 is a missing-authorization flaw (CWE-862) in the Ultimate Member WordPress plugin, rated 7.5 (High), affecting all versions ≤ 2.13.1.
- The root cause is a nonce (
um-frontend-nonce) that is handed out to every visitor, authenticated or not — so it cannot function as an access-control check for thewp_ajax_nopriv_um_get_membersendpoint. - Exploitation requires no authentication, no privileges, and no user interaction — only network access to a vulnerable site.
- Impact is limited to confidentiality (disclosure of privacy-restricted profile fields) — there is no integrity or availability impact.
- The fix is available in Ultimate Member 2.14.0; administrators should update immediately and audit logs for prior scraping activity.
- This is a separate issue from CVE-2026-96270 (stored XSS via
form_id), also affecting Ultimate Member ≤ 2.13.1 — both should be remediated by the same 2.14.0 update, but they are distinct vulnerabilities.