VYPR
Unrated severityNVD Advisory· Published Jul 4, 2023· Updated Nov 25, 2024

Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation

CVE-2023-3460

Description

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.