Executive Summary
CVE-2026-96270 is a stored Cross-Site Scripting (XSS) vulnerability in the Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership plugin for WordPress, affecting all versions up to and including 2.13.1. The flaw lives in the plugin's form_id parameter and stems from insufficient input sanitization and output escaping. Disclosed by Wordfence and published via NVD on October 3, 2026, the issue carries a CVSS v3.1 score of 7.2 (High).
What makes this bug notable is its unauthenticated, delayed-trigger design: an attacker does not need any account or privileges to plant the payload — they simply submit it during the public registration process — and the injected script does not execute immediately. Instead, it lies dormant in the WordPress database until a site administrator opens the affected user's record in the wp-admin Users modal, at which point the unescaped payload runs in the admin's authenticated browser session. The plugin vendor has released a fix in version 2.14.0.
This advisory covers CVE-2026-96270 only. A separate, related finding — CVE-2026-93428, an authorization bypass also affecting Ultimate Member ≤ 2.13.1 — is tracked in its own advisory and is not discussed further here.
Vulnerability Details
| Field | Detail |
|---|---|
| CVE ID | CVE-2026-96270 |
| Vulnerability Type | Stored Cross-Site Scripting (CWE-79: Improper Neutralization of Input During Web Page Generation) |
| CVSS Score | 7.2 (High) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
| Affected Product | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership (WordPress plugin) |
| Affected Versions | All versions ≤ 2.13.1 |
| Fixed Version | 2.14.0 |
| Vulnerable Parameter | form_id |
| Attacker Privileges Required | None — exploitable by an unauthenticated visitor during registration |
| User Interaction Required | None from the attacker; the victim (an administrator) must open the affected user record in wp-admin |
| Assigner | Wordfence |
| Disclosure Timeline | Vendor notified 2026-09-22; publicly disclosed 2026-10-02; published to NVD 2026-10-03 |
| Exploitation Status | Not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog; no public proof-of-concept exploit identified at time of writing |
How It Works
1. Payload Submission During Registration
Ultimate Member builds its registration, login, and profile forms dynamically and tracks which form template rendered a given submission using the form_id field. Because the plugin does not adequately sanitize this value on input or escape it on output, an attacker can submit a registration request where form_id contains a malicious script payload instead of a legitimate numeric form identifier. Critically, this step requires no authentication — anyone who can reach the site's public registration endpoint can submit the crafted value.
2. Storage in User Metadata
Once submitted, the plugin writes the registration data — including the attacker-controlled form_id value — into the newly created user's metadata via WordPress's update_user_meta() function, under the submitted meta key. At this point the malicious payload is persisted in the WordPress database, attached to a real (if attacker-created) user account. No code executes yet; the payload simply waits.
3. Delayed Execution in wp-admin
The vulnerability's dangerous half is on the read side. When a site administrator opens the Users screen in wp-admin and views the affected account's detail modal, Ultimate Member retrieves the stored submitted usermeta and renders it into the admin interface using jQuery's .html() method — without escaping it first. Because .html() interprets its argument as markup rather than plain text, the attacker's stored script runs in that moment, inside the administrator's authenticated browser session.
This delayed-trigger pattern is what distinguishes the bug from a typical reflected or immediately-executing stored XSS: the payload can sit inert in the database for an extended period, and will only fire the next time — or the first time — an administrator happens to inspect that particular user record. A single malicious registration can therefore remain a latent threat across multiple admin sessions until the account is reviewed, deleted, or the plugin is patched.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Limited (C:L) — script execution in an admin session could read page content, cookies accessible to JavaScript, or nonces exposed in the DOM |
| Integrity | Limited (I:L) — an executed payload could perform actions the admin is authorized to perform, such as creating additional administrator accounts or modifying settings, if chained with further requests |
| Availability | None (A:N) — the vulnerability does not directly cause denial of service |
| Scope | Changed (S:C) — the impact extends beyond the vulnerable component itself, into the administrator's broader authenticated session |
| Attack Surface | Broad — any site running Ultimate Member with public self-registration enabled exposes the vulnerable entry point to unauthenticated visitors |
| Detection Difficulty | Elevated — because execution is delayed and tied to an administrative action rather than the initial request, the payload can be easy to miss in standard web application firewall (WAF) logging that focuses on the request that stores the data rather than the page that renders it |
Recommendations
For WordPress Site Administrators
- Update immediately. Upgrade the Ultimate Member plugin to version 2.14.0 or later, which contains the fix for CVE-2026-96270.
- Audit recent registrations. Review user accounts created since the vulnerability's disclosure window (and ideally further back) for anomalous
form_idvalues or other suspicious metadata before opening their profiles in wp-admin. - Restrict registration if patching is delayed. If immediate patching is not possible, consider temporarily disabling public self-registration via Ultimate Member, or placing a web application firewall rule in front of the registration endpoint to filter script-like content in the
form_idfield. - Limit who can access the Users admin screen. Reducing the number of accounts with
list_users/edit_userscapability reduces the number of sessions that could be exposed to the delayed trigger.
For Security Teams
- Inventory Ultimate Member deployments. Identify every WordPress site under management running the plugin and confirm the installed version against 2.14.0.
- Add detection for the pattern. Where feasible, monitor for script-like content (
<script,javascript:, event-handler attributes) submitted in registration form fields, including non-obvious fields likeform_id, rather than relying solely on visible profile fields. - Treat admin-session XSS as a privilege-escalation risk. Because the trigger fires inside an authenticated administrator's browser, incident response playbooks should treat successful exploitation as a potential precursor to full site compromise, not merely a cosmetic defacement risk.
For End Users / Plugin Operators
- Keep plugins current. This is the latest in a series of stored XSS findings against Ultimate Member (including earlier, separately tracked CVEs); maintaining an up-to-date patch cadence for this plugin specifically is warranted given its history.
- Review third-party plugin permissions periodically. Plugins that handle public-facing registration and render user-submitted data in administrative screens warrant closer scrutiny during routine security reviews.
Key Takeaways
- CVE-2026-96270 is an unauthenticated, stored XSS vulnerability in the Ultimate Member WordPress plugin, scoring 7.2 (High) on CVSS v3.1.
- The flaw is exploitable via the
form_idparameter during the public registration process — no attacker authentication is required. - The payload is stored in user metadata via
update_user_meta()and only executes later, when an administrator opens the affected account in the wp-admin Users modal, due to unescaped rendering via jQuery.html(). - All versions ≤ 2.13.1 are affected; the vendor has shipped a fix in version 2.14.0.
- As of publication, the vulnerability is not listed in CISA's KEV catalog and no public exploit code has been identified — but site administrators should still patch promptly given the low exploitation bar (no authentication, no user interaction from the attacker).
- This advisory does not cover CVE-2026-93428, a separate authorization-bypass vulnerability also affecting Ultimate Member ≤ 2.13.1, which is documented independently.