SECURITYHIGHCVE-2026-96270

CVE-2026-96270: Unauthenticated Stored XSS in Ultimate Member via form_id

Unauthenticated stored XSS in Ultimate Member (≤ 2.13.1) via form_id fires when admins open the Users page in wp-admin. Patched in 2.14.0.

Dylan H.

Security Team

October 3, 2026
7 min read
CVE-2026-96270: Unauthenticated Stored XSS in Ultimate Member via form_id

Affected Products

  • Ultimate Member plugin for WordPress, versions ≤ 2.13.1

Executive Summary

CVE-2026-96270 is a stored Cross-Site Scripting (XSS) vulnerability in the Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership plugin for WordPress, affecting all versions up to and including 2.13.1. The flaw lives in the plugin's form_id parameter and stems from insufficient input sanitization and output escaping. Disclosed by Wordfence and published via NVD on October 3, 2026, the issue carries a CVSS v3.1 score of 7.2 (High).

What makes this bug notable is its unauthenticated, delayed-trigger design: an attacker does not need any account or privileges to plant the payload — they simply submit it during the public registration process — and the injected script does not execute immediately. Instead, it lies dormant in the WordPress database until a site administrator opens the affected user's record in the wp-admin Users modal, at which point the unescaped payload runs in the admin's authenticated browser session. The plugin vendor has released a fix in version 2.14.0.

This advisory covers CVE-2026-96270 only. A separate, related finding — CVE-2026-93428, an authorization bypass also affecting Ultimate Member ≤ 2.13.1 — is tracked in its own advisory and is not discussed further here.


Vulnerability Details

FieldDetail
CVE IDCVE-2026-96270
Vulnerability TypeStored Cross-Site Scripting (CWE-79: Improper Neutralization of Input During Web Page Generation)
CVSS Score7.2 (High)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Affected ProductUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership (WordPress plugin)
Affected VersionsAll versions ≤ 2.13.1
Fixed Version2.14.0
Vulnerable Parameterform_id
Attacker Privileges RequiredNone — exploitable by an unauthenticated visitor during registration
User Interaction RequiredNone from the attacker; the victim (an administrator) must open the affected user record in wp-admin
AssignerWordfence
Disclosure TimelineVendor notified 2026-09-22; publicly disclosed 2026-10-02; published to NVD 2026-10-03
Exploitation StatusNot listed in CISA's Known Exploited Vulnerabilities (KEV) catalog; no public proof-of-concept exploit identified at time of writing

How It Works

1. Payload Submission During Registration

Ultimate Member builds its registration, login, and profile forms dynamically and tracks which form template rendered a given submission using the form_id field. Because the plugin does not adequately sanitize this value on input or escape it on output, an attacker can submit a registration request where form_id contains a malicious script payload instead of a legitimate numeric form identifier. Critically, this step requires no authentication — anyone who can reach the site's public registration endpoint can submit the crafted value.

2. Storage in User Metadata

Once submitted, the plugin writes the registration data — including the attacker-controlled form_id value — into the newly created user's metadata via WordPress's update_user_meta() function, under the submitted meta key. At this point the malicious payload is persisted in the WordPress database, attached to a real (if attacker-created) user account. No code executes yet; the payload simply waits.

3. Delayed Execution in wp-admin

The vulnerability's dangerous half is on the read side. When a site administrator opens the Users screen in wp-admin and views the affected account's detail modal, Ultimate Member retrieves the stored submitted usermeta and renders it into the admin interface using jQuery's .html() method — without escaping it first. Because .html() interprets its argument as markup rather than plain text, the attacker's stored script runs in that moment, inside the administrator's authenticated browser session.

This delayed-trigger pattern is what distinguishes the bug from a typical reflected or immediately-executing stored XSS: the payload can sit inert in the database for an extended period, and will only fire the next time — or the first time — an administrator happens to inspect that particular user record. A single malicious registration can therefore remain a latent threat across multiple admin sessions until the account is reviewed, deleted, or the plugin is patched.


Impact Assessment

Impact AreaDescription
ConfidentialityLimited (C:L) — script execution in an admin session could read page content, cookies accessible to JavaScript, or nonces exposed in the DOM
IntegrityLimited (I:L) — an executed payload could perform actions the admin is authorized to perform, such as creating additional administrator accounts or modifying settings, if chained with further requests
AvailabilityNone (A:N) — the vulnerability does not directly cause denial of service
ScopeChanged (S:C) — the impact extends beyond the vulnerable component itself, into the administrator's broader authenticated session
Attack SurfaceBroad — any site running Ultimate Member with public self-registration enabled exposes the vulnerable entry point to unauthenticated visitors
Detection DifficultyElevated — because execution is delayed and tied to an administrative action rather than the initial request, the payload can be easy to miss in standard web application firewall (WAF) logging that focuses on the request that stores the data rather than the page that renders it

Recommendations

For WordPress Site Administrators

  1. Update immediately. Upgrade the Ultimate Member plugin to version 2.14.0 or later, which contains the fix for CVE-2026-96270.
  2. Audit recent registrations. Review user accounts created since the vulnerability's disclosure window (and ideally further back) for anomalous form_id values or other suspicious metadata before opening their profiles in wp-admin.
  3. Restrict registration if patching is delayed. If immediate patching is not possible, consider temporarily disabling public self-registration via Ultimate Member, or placing a web application firewall rule in front of the registration endpoint to filter script-like content in the form_id field.
  4. Limit who can access the Users admin screen. Reducing the number of accounts with list_users / edit_users capability reduces the number of sessions that could be exposed to the delayed trigger.

For Security Teams

  1. Inventory Ultimate Member deployments. Identify every WordPress site under management running the plugin and confirm the installed version against 2.14.0.
  2. Add detection for the pattern. Where feasible, monitor for script-like content (<script, javascript:, event-handler attributes) submitted in registration form fields, including non-obvious fields like form_id, rather than relying solely on visible profile fields.
  3. Treat admin-session XSS as a privilege-escalation risk. Because the trigger fires inside an authenticated administrator's browser, incident response playbooks should treat successful exploitation as a potential precursor to full site compromise, not merely a cosmetic defacement risk.

For End Users / Plugin Operators

  1. Keep plugins current. This is the latest in a series of stored XSS findings against Ultimate Member (including earlier, separately tracked CVEs); maintaining an up-to-date patch cadence for this plugin specifically is warranted given its history.
  2. Review third-party plugin permissions periodically. Plugins that handle public-facing registration and render user-submitted data in administrative screens warrant closer scrutiny during routine security reviews.

Key Takeaways

  1. CVE-2026-96270 is an unauthenticated, stored XSS vulnerability in the Ultimate Member WordPress plugin, scoring 7.2 (High) on CVSS v3.1.
  2. The flaw is exploitable via the form_id parameter during the public registration process — no attacker authentication is required.
  3. The payload is stored in user metadata via update_user_meta() and only executes later, when an administrator opens the affected account in the wp-admin Users modal, due to unescaped rendering via jQuery .html().
  4. All versions ≤ 2.13.1 are affected; the vendor has shipped a fix in version 2.14.0.
  5. As of publication, the vulnerability is not listed in CISA's KEV catalog and no public exploit code has been identified — but site administrators should still patch promptly given the low exploitation bar (no authentication, no user interaction from the attacker).
  6. This advisory does not cover CVE-2026-93428, a separate authorization-bypass vulnerability also affecting Ultimate Member ≤ 2.13.1, which is documented independently.

Sources