CVE-2024-2123 Overview
The Ultimate Member plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 2.8.3. The flaw resides in several parameters within the member directory templates where user-controlled input is not properly sanitized before being rendered in output. Unauthenticated attackers can inject arbitrary JavaScript that executes in the browser of any user visiting an affected page. The vulnerability is tracked under [CWE-79] and has an Exploit Prediction Scoring System (EPSS) probability of 26.666%.
Critical Impact
Unauthenticated attackers can inject persistent JavaScript into WordPress pages using the Ultimate Member plugin, enabling session hijacking, credential theft, and administrative account takeover when a privileged user views the injected content.
Affected Products
- Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress
- All versions up to and including 2.8.3
- Vendor: ultimatemember
Discovery Timeline
- 2024-03-13 - CVE-2024-2123 published to the National Vulnerability Database
- 2024-03-13 - Vendor released fix in changeset 3046611
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-2123
Vulnerability Analysis
The vulnerability is a Stored Cross-Site Scripting flaw in the Ultimate Member WordPress plugin. The plugin's member directory templates render several parameters into HTML without adequate input sanitization or output escaping. An unauthenticated attacker can submit crafted payloads through these parameters, and the malicious script is stored server-side and later executed in the context of the WordPress site.
Because the attack is unauthenticated and stored, any visitor loading the affected member directory page triggers execution. When an administrator views the injected content, the payload runs with administrative privileges within the browser session, enabling session token theft, forced actions via the WordPress REST API, or redirection to attacker-controlled infrastructure.
Root Cause
The root cause is insufficient input sanitization and output escaping in the members-grid.php and members-list.php templates. Specifically, parameter values referenced at lines 44, 53, and 65 of members-grid.php and lines 39 and 53 of members-list.php are echoed into the response without WordPress escaping helpers such as esc_attr() or esc_html(). This allows raw HTML and JavaScript to reach the DOM.
Attack Vector
The attack vector is network-based and requires user interaction to trigger execution. An attacker submits a crafted request that persists the payload in the plugin's data structures. When any user, including administrators, subsequently loads the member directory page, the browser parses and executes the stored script. No authentication is required to deliver the payload.
No proof-of-concept exploit code is publicly linked in the referenced advisories. For technical specifics, refer to the Wordfence Vulnerability Report and the vulnerable template locations documented in the WordPress Plugin Trac.
Detection Methods for CVE-2024-2123
Indicators of Compromise
- Unexpected <script> tags, javascript: URIs, or event-handler attributes (for example onerror, onload) stored in Ultimate Member profile fields or directory parameters.
- Outbound requests from WordPress visitors to unfamiliar domains shortly after loading pages that render the member directory.
- WordPress admin accounts exhibiting unauthorized configuration changes, plugin installations, or new administrator user creations.
Detection Strategies
- Inspect the wp_usermeta and Ultimate Member option tables for HTML markup or JavaScript syntax within fields that should contain plain text.
- Deploy a Web Application Firewall (WAF) with rules that flag XSS payloads targeting Ultimate Member endpoints and directory query parameters.
- Enforce a Content Security Policy (CSP) that blocks inline scripts and unauthorized script origins to surface injection attempts in browser reports.
Monitoring Recommendations
- Log and review all HTTP requests to pages rendering the members-grid.php and members-list.php templates for anomalous query strings.
- Monitor WordPress audit logs for changes to user metadata originating from unauthenticated sessions.
- Correlate web server logs with endpoint telemetry to identify browser exploitation chains initiated from injected pages.
How to Mitigate CVE-2024-2123
Immediate Actions Required
- Update the Ultimate Member plugin to a version newer than 2.8.3 that includes the fix from changeset 3046611.
- Audit member directory pages, user profile fields, and plugin option values for stored XSS payloads and remove any injected content.
- Rotate WordPress administrator credentials and invalidate active sessions if compromise is suspected.
Patch Information
The vendor addressed the vulnerability in the code committed under WordPress Change Set 3046611. The patch adds proper escaping to the affected template parameters in the members directory templates. Administrators should install the fixed release through the WordPress plugin manager and confirm the deployed version in wp-admin.
Workarounds
- Temporarily disable the Ultimate Member plugin if patching cannot be performed immediately.
- Restrict access to member directory pages using authentication requirements or IP allowlists at the reverse proxy.
- Deploy WAF signatures that block requests containing HTML tags or JavaScript event handlers in parameters submitted to the plugin.
# Example WAF rule (ModSecurity) to block script tags in Ultimate Member parameters
SecRule REQUEST_URI "@contains /members" \
"phase:2,deny,status:403,id:2024002123,\
msg:'Potential XSS targeting Ultimate Member (CVE-2024-2123)',\
chain"
SecRule ARGS "@rx (?i)(<script|javascript:|onerror\s*=|onload\s*=)" \
"t:none,t:urlDecodeUni,t:htmlEntityDecode"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.