Ultimate Member <= 2.0.39 - Privilege Escalation

Improper Privilege Management
CVE CVE-2019-10270
CVSS High (8.8)
Publicly Published June 15, 2019
Last Updated January 22, 2024
Researcher Clément CRUCHET
Description

An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.0.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id parameter) to reset the password of another user. One only needs to know the user_id, which is publicly available. One just has to intercept the password modification request and modify user_id. It is possible to modify the passwords for any users or admin WordPress Ultimate Members. This could lead to account compromise and privilege escalation.

References

1 affected software package

Software Type Plugin
Software Slug ultimate-member (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.0.39
Patched Version
  • 2.0.40
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.