Ultimate Member WordPress Plugin Blind SQL Injection Vulnerability

Vulnerability

A blind SQL injection vulnerability has been identified in the Ultimate Member WordPress plugin, specifically in the Member Directory feature. This vulnerability affects all versions of the plugin up to and including 2.10.1. The issue arises from inadequate escaping of user-supplied input in the search parameter, allowing unauthenticated attackers to inject additional SQL queries. Exploitation of this vulnerability could lead to unauthorized access to sensitive information in the database. Notably, this vulnerability was partially addressed in version 2.9.2, which aimed to fix a related issue (CVE-2025-0308).

Impact

Exploitation of this vulnerability allows for blind SQL injection, where an attacker can manipulate SQL queries to extract sensitive information from the database without directly seeing the results of the injection.

Reproduction

To reproduce this vulnerability, send a request to a WordPress site with the Ultimate Member plugin active, version 2.10.1 or earlier. Include a crafted search parameter that exploits the SQL injection vulnerability by appending additional SQL commands to the original query. The lack of proper input sanitization and query preparation will allow the injected SQL to be executed, potentially leading to the extraction of sensitive database information.

Remediation

Users are advised to update the Ultimate Member WordPress plugin to version 2.10.2 or a newer patched version.

Added: Jul 10, 2026, 5:45 AM
Updated: Jul 10, 2026, 5:45 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
9.3
remediation
7.7
relevance
9.4
threat
4.8
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.