← Back to search

CVE-2026-85680

8.8 HIGH

Published 2026-09-19 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows unauthenticated attackers to inject JavaScript into the page title, potentially leading to cross-site scripting (XSS) attacks.
Exploitability
Exploitation is relatively easy as it requires an attacker to register an account and craft a malicious profile name. Precondition is the target must be using a version of the Ultimate Member plugin before 2.13.1.
Blast radius
If exploited, the attack could impact any visitor, including administrators, who view the profile of the attacker's account, potentially leading to data theft or further exploitation.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Ultimate Member 2.13.1 or later.
xsswebwp-plugin

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-79

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.