Over 200,000 WordPress Accounts at Risk Thanks to Plugin Vulnerability

We may receive a commission from our partners if you click on a link and purchase a product or service on their website. Learn more

headshot of Sam Jagger
Written By
Updated on July 13, 2023
A creepy illustrated man steps out form inside a phone next to the WordPress logo
  • Ultimate Member, a WordPress plugin with over 200,000 active installations, has had a security vulnerability exploited by hackers.
  • The vulnerability allowed hackers to gain admin-level privileges to all the user’s accounts and websites, even after a patch intended to stop them was released on June 28th.

Ultimate Member, a membership area plugin for WordPress, has had a security vulnerability exploited by hackers, giving them access to over 200,000 active users’ websites and account information. 

Ultimate Member is a popular membership plugin allowing users to create subscription sites and membership areas for their visitors. However, a fatal flaw was discovered in which visitors could essentially give themselves Administrator clearance across the site, giving them full access to the site’s information and also the original owner’s personal information. 

WordPress users rely on plugins for most of their website’s features, so potential safety flaws in one could expose flaws in others, which is a scary reality that WordPress users had to face in light of this news.

Wordfence, a global team of WordPress security experts and analysts, described the steps the hackers were taking to get Administrator access – the highest level of clearance on a WordPress site – as “trivial”. 

The Ultimate Member publishers found the patch by late June 2023, but by that point, it was too late. An update patch released on the 28th of June was intended to fix it, but Wordfence analysts later revealed that it had done nothing, stating:

“Upon further investigation, we discovered that this vulnerability is being actively exploited and it hasn’t been adequately patched in the latest version available, which is 2.6.6 at the time of this writing”

The Ultimate Member publishers issued a public apology on behalf of those users affected, saying that they had

“released several updates since the disclosure as we worked through the vulnerabilities”.

As of yet, the exploits are still ongoing. The current advice for those that have the plugin is to uninstall it immediately. 

Written By

headshot of Sam Jagger

Hi, I’m Sam:

Samuel Jagger is a Senior Writer at Website Builder Expert, specializing in AI integration and web design theory. He has created editorial content for the publication since 2022 and has covered topics ranging from website design, ecommerce, digital marketing, and more. He’s written articles for apps like UXPin on web design in the modern age, as well as answered over 100 user comments on the site. Sam has also created his own websites, such as this Strikingly demo you can view here. He also writes and stars in the official WBE TikToks, sharing helpful website tips and commenting on the latest in website design news.

Previously, Samuel worked as a Freelance Blog Writer for The MIZU Hub and as a Digital Content Creator for Europa Music Management, working with musical artists like Purple Disco Machine, David Penn, and Monolink. Samuel has a Master of Arts in Creative Writing and a Bachelor of Arts in Film Practices from Newcastle University, where he graduated with honors and distinction.

Samuel is passionate about writing, visual media, and the creative arts. He is always looking for new avenues to funnel his creativity and align his skills with projects that interest him. You can find him and keep up to date with what he’s up to on his LinkedIn.

More about

0 comments

Your email address will not be published. Required fields are marked *