CVE-2026-85680
8.8 HIGHPublished 2026-09-19 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows unauthenticated attackers to inject JavaScript into the page title, potentially leading to cross-site scripting (XSS) attacks.
- Exploitability
- Exploitation is relatively easy as it requires an attacker to register an account and craft a malicious profile name. Precondition is the target must be using a version of the Ultimate Member plugin before 2.13.1.
- Blast radius
- If exploited, the attack could impact any visitor, including administrators, who view the profile of the attacker's account, potentially leading to data theft or further exploitation.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Ultimate Member 2.13.1 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-79
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-88824
- MEDIUMCVE-2025-71419PoC
- MEDIUMCVE-2026-16069
- HIGHCVE-2026-16143
- MEDIUMCVE-2026-16293
- HIGHCVE-2026-16573
- CRITICALCVE-2026-18872
- MEDIUMCVE-2026-36468PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.