AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-11766

HIGH · CVSS 8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

The Ultimate Member WordPress plugin prior to version 2.12.0 is vulnerable due to inadequate sanitization of custom textarea profile fields, enabling authenticated users with Subscriber-level access or higher to inject malicious JavaScript. This flaw can lead to cross-site scripting (XSS) attacks, potentially compromising user sessions and exposing sensitive information when profiles are viewed. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate the risk.

CVE
CVE-2026-11766
Severity
HIGH
CVSS
8
EPSS
0.23%
WordPress Java

Original NVD Description

The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator, views the affected profile.