PT-2025-51859 · WordPress · The Ultimate Member

Kevin Wydler

·

Published

2025-12-17

·

Updated

2025-12-17

·

CVE-2025-13217

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress versions prior to 2.11.1
Description The software is susceptible to a Stored Cross-Site Scripting issue. Insufficient input sanitization and output escaping on user-supplied YouTube video URLs allows authenticated attackers with Subscriber-level access or higher to inject arbitrary web scripts. These scripts execute when a user accesses the profile page of the user who injected the script. The issue is related to the YouTube Video 'value' field and the um profile field filter hook youtube video() function.
Recommendations Update The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress to version 2.11.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-13217

Affected Products

The Ultimate Member