🔐 CVE Alert

CVE-2026-1404

MEDIUM 6.1

Ultimate Member <= 2.11.1 - Reflected Cross-Site Scripting via Filter Parameters

CVSS Score
6.1
EPSS Score
0.1%
EPSS Percentile
21th

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CWE CWE-79
Vendor ultimatemember
Product ultimate member – user profile, registration, login, member directory, content restriction & membership plugin
Published Feb 18, 2026
Last Updated Feb 18, 2026

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ultimatemember / Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
* ≤ 2.11.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/ba62b804-f101-4e29-8304-fb2b7dad333c?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-member/trunk/templates/members.php#L348 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-member/trunk/assets/js/um-members.js#L515 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3458086/

Credits

Dmitrii Ignatyev