VYPR
Medium severity5.5NVD Advisory· Published May 7, 2025· Updated Apr 23, 2026

CVE-2025-47691

CVE-2025-47691

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A code injection vulnerability in Ultimate Member plugin for WordPress (<=2.10.3) allows unauthenticated attackers to execute arbitrary code via improper input handling.

Vulnerability

Overview

The Ultimate Member plugin for WordPress, versions 2.10.3 and earlier, contains a code injection vulnerability due to improper control of code generation. This allows an attacker to inject arbitrary PHP code through unsanitized user input [1].

Exploitation

The vulnerability can be exploited remotely without authentication. An attacker sends specially crafted requests to the plugin's endpoints, bypassing input validation to inject code that gets executed on the server. No special privileges or network position is required beyond access to the WordPress site [1].

Impact

Successful exploitation leads to arbitrary code execution, giving the attacker full control over the affected WordPress site. This can result in data theft, site defacement, malware distribution, and further compromise of the server. The vulnerability is actively used in mass-exploit campaigns targeting thousands of sites [1].

Mitigation

The vendor has released a patched version. Users should update Ultimate Member to version 2.10.4 or later immediately. If updating is not possible, consult with a hosting provider or security professional for temporary workarounds [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.