Ultimate Member WordPress Plugin Time-Based SQL Injection Vulnerability

Vulnerability

A time-based SQL injection vulnerability has been identified in the Ultimate Member WordPress plugin, specifically in versions through 2.9.1. The vulnerability arises from inadequate escaping of user-supplied data in the search parameter, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.

Impact

Exploitation of this vulnerability could allow an attacker to manipulate SQL queries, potentially leading to unauthorized data access or disclosure of sensitive information from the WordPress database.

Reproduction

To reproduce this vulnerability, send a request to a member directory that uses the Ultimate Member plugin version 2.9.1 or earlier. Include a crafted search parameter that exploits the SQL injection vulnerability by appending additional SQL commands. The injection can be verified by extracting data from the database, such as user information or other sensitive details.

Remediation

Users are advised to update the Ultimate Member WordPress plugin to version 2.9.2 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
9.3
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.