Vulnerability record · CVE-2023-3460 · published 4 July 2023
CVE-2023-3460: Ultimate Member WordPress plugin privilege escalation via arbitrary capabilities
Ultimatemember · Ultimate Member
The Ultimate Member WordPress plugin before 2.6.7 fails to restrict the capabilities assigned to newly registered user accounts, letting any visitor create an account with administrator-level privileges. Because this allows full site takeover without any prior access, it is a severe risk to any unpatched WordPress site running the plugin. The record states the flaw is actively exploited in the wild.
Description
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote attackers can create administrator accounts on unpatched sites, the flaw is reported as actively exploited, and EPSS is very high.
What it is
The Ultimate Member WordPress plugin before 2.6.7 fails to restrict the capabilities assigned to newly registered user accounts, letting any visitor create an account with administrator-level privileges. Because this allows full site takeover without any prior access, it is a severe risk to any unpatched WordPress site running the plugin. The record states the flaw is actively exploited in the wild.
Impact
An unauthenticated attacker can create a new administrator account and then control the WordPress site, including its content, users, and potentially the underlying host. This amounts to complete compromise of the affected installation.
Attack surface
Reachable over the network through the plugin's public user registration functionality; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any site exposing the plugin's registration form is a candidate target.
Exploitation
The description states the flaw is actively being exploited in the wild, and references carry an Exploit tag, though the CVE is not listed in CISA KEV. EPSS is very high at roughly 0.72 (99.4th percentile), indicating strong likelihood of exploitation activity.
What to do
- Update the Ultimate Member plugin to version 2.6.7 or later immediately.
- If patching cannot be done at once, disable or restrict the plugin's public registration functionality until the update is applied.
- Audit existing WordPress user accounts for unexpected administrator accounts and remove any that are not authorized.
- Review site logs and registration records for suspicious account creation around the exposure window.
- Apply the principle of least privilege to WordPress roles and monitor for new administrator-level accounts.
Detection
- Monitor WordPress user creation events for new accounts assigned administrator or other high-privilege roles.
- Alert on registration requests that include unexpected capability or role parameters in the request body.
- Review web server and plugin logs for spikes in registration activity or requests to the plugin's registration endpoints.
- Check for newly created administrator accounts and correlate their creation time with external IP addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.wpscan.com/hacking-campaign-actively-exploiting-ultimate-member-plugin/ | Third Party Advisory |
| https://wpscan.com/vulnerability/694235c7-4469-4ffd-a722-9225b19e98d7 | ExploitPatch |
| https://blog.wpscan.com/hacking-campaign-actively-exploiting-ultimate-member-plugin/ | Third Party Advisory |
| https://wpscan.com/vulnerability/694235c7-4469-4ffd-a722-9225b19e98d7 | ExploitPatch |
Track CVE-2023-3460 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-3460), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.