← Vulnerability feed

Vulnerability record · CVE-2023-3460 · published 4 July 2023

CVE-2023-3460: Ultimate Member WordPress plugin privilege escalation via arbitrary capabilities

Ultimatemember · Ultimate Member

The Ultimate Member WordPress plugin before 2.6.7 fails to restrict the capabilities assigned to newly registered user accounts, letting any visitor create an account with administrator-level privileges. Because this allows full site takeover without any prior access, it is a severe risk to any unpatched WordPress site running the plugin. The record states the flaw is actively exploited in the wild.

9.8 CVSS 3.1 Critical EPSS 72% · top 0.6%
9.8CVSS 3.1 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote attackers can create administrator accounts on unpatched sites, the flaw is reported as actively exploited, and EPSS is very high.

What it is

The Ultimate Member WordPress plugin before 2.6.7 fails to restrict the capabilities assigned to newly registered user accounts, letting any visitor create an account with administrator-level privileges. Because this allows full site takeover without any prior access, it is a severe risk to any unpatched WordPress site running the plugin. The record states the flaw is actively exploited in the wild.

Impact

An unauthenticated attacker can create a new administrator account and then control the WordPress site, including its content, users, and potentially the underlying host. This amounts to complete compromise of the affected installation.

Attack surface

Reachable over the network through the plugin's public user registration functionality; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any site exposing the plugin's registration form is a candidate target.

Exploitation

The description states the flaw is actively being exploited in the wild, and references carry an Exploit tag, though the CVE is not listed in CISA KEV. EPSS is very high at roughly 0.72 (99.4th percentile), indicating strong likelihood of exploitation activity.

What to do

  • Update the Ultimate Member plugin to version 2.6.7 or later immediately.
  • If patching cannot be done at once, disable or restrict the plugin's public registration functionality until the update is applied.
  • Audit existing WordPress user accounts for unexpected administrator accounts and remove any that are not authorized.
  • Review site logs and registration records for suspicious account creation around the exposure window.
  • Apply the principle of least privilege to WordPress roles and monitor for new administrator-level accounts.

Detection

  • Monitor WordPress user creation events for new accounts assigned administrator or other high-privilege roles.
  • Alert on registration requests that include unexpected capability or role parameters in the request body.
  • Review web server and plugin logs for spikes in registration activity or requests to the plugin's registration endpoints.
  • Check for newly created administrator accounts and correlate their creation time with external IP addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-3460 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-1071Ultimate Member WordPress plugin unauthenticated SQL injection via sorting parameterThe Ultimate Member WordPress plugin fails to properly escape the user-supplied 'sorting' parameter and does not sufficiently prepare the resulting S…EPSS 89%analysed9.8CVE-2020-36155Ultimatemember ultimate member improper privilege management vulnerabilityAn issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacke…EPSS 9.0%9.8CVE-2020-36157Ultimatemember ultimate member vulnerabilityAn issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to th…EPSS 3.0%8.8CVE-2023-31216Ultimatemember ultimate member cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.EPSS 0.27%8.8CVE-2020-36156Ultimatemember ultimate member improper privilege management vulnerabilityAn issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any use…EPSS 2.0%8.8CVE-2019-10270Ultimatemember ultimate member weak password recovery vulnerabilityAn arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and co…EPSS 1.2%8.8CVE-2019-10673Ultimatemember ultimate member cross-site request forgery vulnerabilityA CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become adm…EPSS 1.8%7.5CVE-2025-0308Ultimatemember ultimate member sql injection vulnerabilityThe Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2023-3460), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.