天下漏洞,尽知其名
HIGH

CVE-2026-93428 Ultimate Member 授权绕过漏洞

影响未授权攻击者可查看受隐私保护的会员资料字段

AI 研判

WordPress 插件 Ultimate Member 在 2.13.1 及之前版本中存在授权绕过漏洞。插件未正确校验用户是否有权执行相关操作,导致未认证攻击者可读取本应受限的会员资料字段。

影响范围

Ultimate Member

Ultimate Member 插件所有版本至 2.13.1(含)。

漏洞详情

漏洞源于插件未正确验证用户权限,属于授权绕过。公开可访问的 wp_ajax_nopriv_um_get_members 接口所需 nonce(um-frontend-nonce)通过 wp_localize_script 下发给所有未认证访客,无法起到访问控制作用,任何匿名访问者均可满足该接口的认证要求,从而查询并获取被配置为仅本人、仅会员或按角色限制的会员资料字段值。

利用条件与风险

利用无需认证,攻击者只需访问公开接口即可读取隐私受限的会员资料,实战中可导致敏感信息泄露。

修复建议

建议升级至 2.13.1 之后的修复版本;若暂无可用更新,可限制对相关 AJAX 接口的访问或暂时禁用会员目录相关功能作为临时缓解。

原始情报

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view privacy-restricted member profile field values — including fields explicitly configured as owner-only, members-only, or role-restricted — by querying the publicly accessible wp_ajax_nopriv_um_get_members endpoint. The nonce required by the endpoint (‘um-frontend-nonce’) is emitted to all unauthenticated visitors via wp_localize_script, meaning it provides no meaningful access control and any anonymous visitor can satisfy the endpoint’s authentication requirements.