ZeroHour

CVE-2023-3460

PoC
CVSS 3.1
9.8 critical
EPSS
72%p99
Published
()
Modified
Description

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

Vendors
ultimatemember
Products
ultimate member
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news