OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-85680

HIGH · CVSS 8.8 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Ultimate Member WordPress plugin prior to version 2.13.1 is vulnerable due to improper escaping of user-supplied profile names, which can lead to stored cross-site scripting (XSS) attacks. This flaw allows unauthenticated attackers to inject malicious JavaScript that executes when any visitor, including administrators, views the compromised profile. WordPress site administrators and users of the Ultimate Member plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-85680
Severity
HIGH
CVSS
8.8
EPSS
0.51%
WordPress Java

Original NVD Description

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.