CVE-2023-3460
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.
- Affected products
- Ultimate Member
- Ultimatemember Ultimate Member
- < 2.6.7
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 72.3% (99th percentile)
- NVD status
- Modified
- Published
- 2023-07-04
CVE-2023-3460 at NVD
21 known exploits for CVE-2023-3460
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2023-3460
Mass-CVE-2023-3460
CVE-2023-3460
CVE-2023-3460
CVE-2023-3460
CVE-2023-3460
CVE-2023-3460
CVE-2023-3460_FIX
exploit-CVE-2023-3460
CVE-2023-3460_POC
π WordPress Ultimate Member 2.6.6 Privilege Escalation
Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation
Exploit for CVE-2023-3460
Exploit for CVE-2023-3460
Exploit for CVE-2023-3460
Exploit for CVE-2023-3460
Exploit for CVE-2023-3460
Exploit for CVE-2023-3460
Exploit for CVE-2023-3460
Exploit for CVE-2023-3460
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation