The Ultimate Member Plugin Has A Critical Security Vulnerability
WPScan currently reports an active hacking campaign exploiting an unpatched vulnerability in the Ultimate Member plugin. WPScan has discovered that the Ultimate Member plugin has a critical security vulnerability, allowing unauthorized attackers to create new user accounts with administrative privileges. This enables the attacker to take control of the entire website (https://blog.wpscan.com/hacking-campaign-actively-exploiting-ultimate-member-plugin/). The vulnerability is assigned a CVSSv3.1 (Common Vulnerability Scoring System) score of 9.8, indicating its critical nature. Hosting platforms like WP.cloud and Pressable.com by Automattic have noticed patterns in compromised websites, where unauthorized site administrators were appearing. After further investigation, the platform’s staff … Read more