A weakness in the well-known Ultimate Member WordPress plugin allows attackers with authenticated contributor-level access or higher to take over accounts by revealing password reset links.
The vulnerability impacts around 200,000 WordPress installations and has a severity rating of 8.8 out of 10.
Ultimate Member Plugin for WordPress
Ultimate Member is a plugin for WordPress designed to assist websites in establishing online communities, membership portals, and user directories by offering features such as front-end registration, login, profiles, and searchable member directories. Additionally, it allows users to become authors and contribute by creating posts and comments.
Exposed to authenticated attackers
Attackers must obtain contributor-level permissions before exploiting this verified vulnerability, which, when successfully exploited, allows for complete website account takeover.
Disclosure of Password Reset Link
The vulnerability arises from three distinct logic flaws that pose a threat when combined.
Attackers can deceive the plugin into recognizing any posts as authorized member directories by exploiting a vulnerability. This flaw enables them to redirect directory functions to content under their control.
Attackers can bypass restrictions on protected metadata fields in WordPress, enabling them to access internal information that plugins typically prevent normal users from altering.
The third issue arises from not correctly verifying field names when creating user card information, which allows attackers to access internal fields, such as the password reset link, that should not be publicly exposed.
Impact Of Being Vulnerable
Password reset links function as temporary login credentials and should remain confidential, being sent solely to the account owner for password recovery purposes.
The plugin’s lack of proper validation for requested fields allows attackers to uncover reset links, enabling them to reset any account’s password, including that of an administrator with website access privileges.
According to Wordfence:
Attackers who are authenticated at Contributor level or higher can share active password reset URLs for all users in the member directory response, including administrators.
A patch is now accessible.
The security flaw impacts all editions of Ultimate Member up to version 2.11.4. A fix is present in version 2.12.0, offering enhanced validation for member directory management and permitted user data fields. Ultimate Member plugin users are advised to promptly upgrade to version 2.12.0 or later.
Image provided by Shutterstock/Luis Molinero



