Ultimate Member <= 2.6.6 - Privilege Escalation via Arbitrary User Meta Updates
2023-06-29 00:00
Marc-Alexandre MontpasStrategic Overview
StatusPatched in 2.6.7
Affected PluginUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Affected Version
<= 2.6.6CVSS9.8Critical
CVE
CVE-2023-3460Vulnerability Overview
The Ultimate Member plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.6. This is due to the plugin using a predefined list of user meta keys that are banned which can be bypassed via a few method like adding slashes to the user meta key. This makes it possible for unauthenticated attackers to register on a site as an administrator.
Technical Analysis
REMEDIATION: Update to version 2.6.7, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C