Summary
CVE-2026-15290 is a high-severity blind SQL injection vulnerability in the Ultimate Member WordPress plugin, affecting all versions up to and including 2.10.1. The flaw allows unauthenticated remote attackers to extract sensitive data from the WordPress database with no privileges and no user interaction required, earning a CVSS v3.1 score of 7.5. With over 200,000 active installations, the potential attack surface is significant.
Technical details
- Root cause: Insufficient escaping of the user-supplied
searchparameter and lack of proper preparation of the existing SQL query within the plugin’s member directory component (class-member-directory.php). This is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). - Trigger conditions: An unauthenticated attacker sends a crafted HTTP POST request to the
um_get_membersAJAX action, injecting malicious SQL via thesearchparameter. No account, session, or prior interaction with the target site is required. - Attack vector: Network-accessible; exploitable remotely against any internet-facing WordPress site running the affected plugin versions.
- Impact: High confidentiality loss. By appending additional SQL queries into already-existing queries, an attacker can extract the full contents of the WordPress database — including usernames, hashed passwords, email addresses, and any other stored data.
- Patch history: A prior fix in version 2.9.2 (addressing CVE-2025-0308) only partially remediated the underlying issue. The search parameter injection path remained exploitable through version 2.10.1.
Affected software
- Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin (WordPress): all versions ≤ 2.10.1
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Update the Ultimate Member plugin to version 2.10.2 or later (current latest: 2.12.1 as of July 6, 2026). This release contains the complete fix for the SQL injection path in the member directory search functionality.
- If immediate patching is not possible: Restrict or disable the member directory feature and block unauthenticated access to the
um_get_membersAJAX endpoint at the web server or WAF layer until the plugin can be updated. - General hardening: Audit WordPress database permissions to ensure the database user has only the minimum required privileges, limiting the data an attacker can extract in the event of exploitation.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

