Sploitus

CVE-2026-4248

No indexed exploits for CVE-2026-4248 yet

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid password reset token for the currently logged-in user viewing the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to craft a malicious pending post that, when previewed by an Administrator, generates a password reset token for the Administrator and exfiltrates it to an attacker-controlled server, leading to full account takeover.

Affected products
Ultimate Member, Wordpress
Fix
Available
CVSS 3.1
8.0 HIGH
EPSS
0.2% (14th percentile)
Weakness
CWE-285
NVD status
Deferred
Published
2026-03-27
CVE-2026-4248 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-4248 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-4248 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.