关键漏洞信息 CVE: CVE-2026-1404 CVSS: 6.1 (Medium) Publicly Published: February 17, 2026 Last Updated: February 18, 2026 Researcher: Dmitrii Ignatyev - CleanTalk Inc 描述 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. 参考资料 plugins.trac.wordpress.org plugins.trac.wordpress.org plugins.trac.wordpress.org 漏洞详细信息 Software Type: Plugin Software Slug: ultimate-member Patched?: Yes Remediation: Update to version 2.11.2, or a newer patched version Affected Version: <= 2.11.1 Patched Version: 2.11.2