---
id: CVE-2026-85680
title: >-
  The Ultimate Member  WordPress plugin before 2.13.1 does not escape a value
  derived from user supplied profile names before outputting it in the page
  title, and decodes HTML entities in it after its own sanitisation has already
  run, allo…
summary: >-
  The Ultimate Member  WordPress plugin before 2.13.1 does not escape a value
  derived from user supplied profile names before outputting it in the page
  title, and decodes HTML entities in it after its own sanitisation has already
  run, allo…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Ultimate Member
affected:
  - ultimate_member < 2.13.1
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:34:57.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85680'
references:
  - url: 'https://wpscan.com/vulnerability/a49b734f-2244-4d6f-8912-b4ce6ba9eb0f/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00276
epssPercentile: 0.20254
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-19T13:12:44.122007Z'
ingestedAt: '2026-09-19T06:59:13.115Z'
---

## Overview

The Ultimate Member  WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that will execute when any visitor, including an administrator, views their profile.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
