SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19423

HIGH · CVSS 8.1 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Ultimate Member WordPress plugin prior to version 2.13.0 is vulnerable due to inadequate validation of role selections, enabling unauthenticated users to exploit this flaw and assign themselves arbitrary capabilities, potentially achieving administrator-level access. This vulnerability poses a significant risk to WordPress sites utilizing the affected plugin, particularly those that allow user registrations through the Ultimate Member forms. Website administrators and security teams should prioritize updating to the latest version to mitigate this critical security risk.

CVE
CVE-2026-19423
Severity
HIGH
CVSS
8.1
EPSS
0.28%
WordPress

Original NVD Description

The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant themselves arbitrary capabilities and reach administrator-equivalent access.