S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-3460 Scanner

Detects 'Privilege Escalation' vulnerability in Ultimate Member plugin for WordPress affects v. before 2.6.7.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-3460
9.8
CVSS

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Ultimate Member
AFFECTED< 2.6.7SAFE ✓≥ 2.6.7
Updated Aug 22, 2026View on NVD →
Detail

The Ultimate Member plugin for WordPress is a popular tool designed to create user profiles, registration forms, and member directories on a website. It's used by website owners to simplify the registration process for users and make it easier to manage member data. With over 100,000 active installations and a 4.6-star plugin rating, it's a go-to plugin for many WordPress users.

However, recently, Ultimate Member plugin has been hit with a critical vulnerability known as CVE-2023-3460. This particular vulnerability allows attackers to easily create user accounts with arbitrary capabilities, providing attackers with full administrator privileges, enabling them to take over entire websites with ease. 

When a hacker exploits this vulnerability, they can execute any function that a WordPress administrator is capable of, including installing malware, deleting files, and even stealing sensitive information. This can cause irreversible damage to a website, leading to loss of revenue, compromised user data, and even potential damage to a website owner's reputation.

In conclusion, the Ultimate Member plugin for WordPress is a popular tool used to create a better experience for website users. However, it has recently been found to have a critical vulnerability that can be exploited by attackers to gain full access to a website. It's essential that website owners protect themselves from this vulnerability by taking proper precautions and keeping their website up to date. For those looking to get an extra layer of security for their website, s4e.io provides pro features that can help detect and protect against vulnerabilities in your digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners should take the following precautions:

  • Update Ultimate Member plugin to the latest version as soon as possible.
  • Ensure that all user accounts on the website are legitimate.
  • Use strong and unique passwords for all user accounts.
  • Turn off user registration on your website if it's not necessary.
  • Deploy a website security solution that scans for vulnerabilities and issues in real-time.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.