{"id":"CVE-2026-85680","published":"2026-09-19T07:16:32.960","lastModified":"2026-09-21T13:34:57.127","description":"The Ultimate Member  WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/a49b734f-2244-4d6f-8912-b4ce6ba9eb0f/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to inject JavaScript into the page title, potentially leading to cross-site scripting (XSS) attacks.","exploitability":"Exploitation is relatively easy as it requires an attacker to register an account and craft a malicious profile name. Precondition is the target must be using a version of the Ultimate Member plugin before 2.13.1.","blast_radius":"If exploited, the attack could impact any visitor, including administrators, who view the profile of the attacker's account, potentially leading to data theft or further exploitation.","remediation":"Upgrade to Ultimate Member 2.13.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["xss","web","wp-plugin"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:20:28.883Z"}}