CVE-2026-4248
Last modified
CVE-2026-4248 is a high-severity vulnerability rated 8/10 on the CVSS scale. The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid password reset token for the currently logged-in user viewing the page. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid password reset token for the currently logged-in user viewing the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to craft a malicious pending post that, when previewed by an Administrator, generates a password reset token for the Administrator and exfiltrates it to an attacker-controlled server, leading to full account takeover.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-4248?
How severe is CVE-2026-4248?
How do I fix CVE-2026-4248?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-42474SQL injection vulnerability in MixPHP Framework 2.x thru 2.2…6.5
- CVE-2026-42475SQL injection vulnerability in MixPHP Framework 2.x thru 2.2…6.5
- CVE-2026-42476Two heap-based out-of-bounds read vulnerabilities in the STL…7.1
- CVE-2026-42477A heap-based out-of-bounds read vulnerability in RWObj_Reade…7.1
- CVE-2026-42478An issue was discovered in VrmlData_IndexedFaceSet::TShape i…7.5
- CVE-2026-42479An out-of-bounds read vulnerability in VrmlData_IndexedLineS…5.5
- CVE-2026-42480A stack-based out-of-bounds read vulnerability in VrmlData_S…5.5
- CVE-2026-42481Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple …5.5
- CVE-2026-42482A stack-based buffer overflow in mangle_to_hex_lower() and m…9.8
- CVE-2026-42483A heap-based buffer overflow in the Kerberos hash parser in …9.8
- CVE-2026-42484A heap-based buffer overflow in hex_to_binary in the PKZIP h…9.8
- CVE-2026-42485AGL agl-service-can-low-level contains a stack buffer overfl…7.5
Are you affected by CVE-2026-4248?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
