Sploitus

CVE-2023-3460

21 known exploits for CVE-2023-3460

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

Affected products
Ultimate Member
Ultimatemember Ultimate Member
< 2.6.7
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
72.3% (99th percentile)
NVD status
Modified
Published
2023-07-04
CVE-2023-3460 at NVD
Authoritative description, scoring and affected products

21 known exploits for CVE-2023-3460

Proof-of-concept code and exploit modules indexed by Sploitus