azzaroco Ultimate Membership Pro
cpe:2.3:a:wpindeed:ultimate_membership_pro:*:*:*:*:wordpress:*:*
- <= 13.7
A vulnerability allowing authentication bypass has been identified in the azzaroco Ultimate Membership Pro plugin, specifically in versions through 13.7. This vulnerability allows for authentication abuse, enabling malicious actors to perform actions typically reserved for higher-privileged users, potentially leading to unauthorized admin access.
Exploitation of this vulnerability could result in unauthorized access to user accounts, with the potential for gaining administrative privileges on the affected WordPress site.
Users of the Ultimate Membership Pro plugin should update to version 13.7.1 or later. Patchstack users can enable auto-update for vulnerable plugins.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.