The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.
CVE-2026-85680
NONE
EPSS 0.17%
Updated Sep 19, 2026
Unknown
unknown:ultimate member
CVE Details
CVE ID
CVE-2026-85680
Published Date
Sep 19, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.17%
Likelihood of exploitation in next 30 days
Percentile:
7.0th percentile (higher than 7.0% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory