CVE-2025-12492
Last modified
CVE-2025-12492 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictable low-entropy token (5 hex characters derived from md5 of post ID) to identify member directories and insufficient authorization checks on the unauthenticated AJAX endpoint. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictable low-entropy token (5 hex characters derived from md5 of post ID) to identify member directories and insufficient authorization checks on the unauthenticated AJAX endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, display names, user roles (including administrator accounts), profile URLs, and user IDs by enumerating predictable directory_id values or brute-forcing the small 16^5 token space.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-12492?
How severe is CVE-2025-12492?
How do I fix CVE-2025-12492?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-12487oobabooga text-generation-webui trust_remote_code Reliance o…9.8
- CVE-2025-12488oobabooga text-generation-webui trust_remote_code Reliance o…9.8
- CVE-2025-12489evernote-mcp-server openBrowser Command Injection Privilege …7.8
- CVE-2025-1249Missing Authorization vulnerability in Marcus (aka @msykes) …5.3
- CVE-2025-12490Netgate pfSense CE Suricata Path Traversal Remote Code Execu…8.8
- CVE-2025-12491Senstar Symphony FetchStoredLicense Information Disclosure V…7.5
- CVE-2025-12493The ShopLentor – WooCommerce Builder for Elementor & Gutenbe…9.8
- CVE-2025-12494The Image Gallery – Photo Grid & Video Gallery plugin for Wo…4.3
- CVE-2025-12495Academy Software Foundation OpenEXR EXR File Parsing Heap-ba…7.8
- CVE-2025-12496The Zephyr Project Manager plugin for WordPress is vulnerabl…4.9
- CVE-2025-12497The Premium Portfolio Features for Phlox theme plugin for Wo…8.1
- CVE-2025-12498The EventPrime – Events Calendar, Bookings and Tickets plugi…4.3
Are you affected by CVE-2025-12492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
