Open Nav
Sign Up

Urgent Security Alert: SQL Injection Vulnerability in WordPress Ultimate Member Plugin (CVE-2024-1071)

Bar Refael

February 26, 2024

A critical unauthenticated SQL Injection vulnerability, identified as CVE-2024-1071, has been discovered in versions 2.1.3 to 2.8.2 of the Ultimate Member WordPress plugin. This vulnerability affects over 200,000 active installations and allows attackers to inject malicious SQL commands through the ‘sorting’ parameter. Successful exploitation could lead to the extraction of sensitive information, including password hashes, from the database.

Vulnerability Details:

  • CVE ID: CVE-2024-1071
  • Affected Versions: Ultimate Member WordPress Plugin versions 2.1.3 to 2.8.2
  • Impact: SQL Injection, Data Exfiltration

Impact:

  • Unauthorized access to sensitive information
  • Potential compromise of user credentials and data
  • Risk of further exploitation and compromise of the affected WordPress sites

Recommendations:

  • Update: Immediately update the Ultimate Member plugin to version 2.8.3 to mitigate the vulnerability.
  • Review: Conduct a security review of your WordPress site to ensure no unauthorized access or changes have occurred.
  • Monitor: Monitor your website for any unusual activity or unauthorized access attempts.
  • Educate: Educate your website administrators and users about safe browsing practices and security measures.

Action Required:

Immediate action is required to update the Ultimate Member plugin to version 2.8.3 to protect your website from potential exploitation. Failure to update could result in unauthorized access to your website and compromise of sensitive information.

Stay Secure. Stay Informed.

OP Innovate Research Team.

Resources highlights

CVE-2026-24061: GNU Inetutils telnetd Remote Authentication Bypass

CVE-2026-24061 is a pre-authentication remote authentication bypass in GNU Inetutils telnetd. The flaw carries a Critical CVSS:3.1 severity score of 9.8 and allows an attacker…

Read more >

CVE-2026-24061

CVE-2026-0227: PAN-OS GlobalProtect Denial-of-Service Vulnerability

CVE-2026-0227 is a high-severity denial-of-service vulnerability affecting Palo Alto Networks PAN-OS and Prisma Access deployments where GlobalProtect Gateway or Portal is enabled. The flaw allows…

Read more >

cve-2026-0227

CVE-2026-20805: Windows Desktop Window Manager (DWM) Zero-Day

CVE-2026-20805 is a Windows Desktop Window Manager (DWM) information disclosure vulnerability that has been exploited in the wild as a zero-day.While the CVSS v3.1 base…

Read more >

cve-2026-20805

CVE-2025-12420 (“BodySnatcher”): Unauthenticated User Impersonation in ServiceNow AI Platform

CVE-2025-12420 is a critical (CVSS 9.3) vulnerability in the ServiceNow AI Platform that can allow a remote, unauthenticated attacker to impersonate another user and then…

Read more >

cve-2025-12420

N8MARE / Ni8mare: Critical n8n Flaw Enables Unauthenticated File Access: CVE-2026-21858

On January 7, 2026, n8n disclosed a critical vulnerability tracked as CVE-2026-21858 (CVSS 10.0), dubbed “Ni8mare” (often referenced as “N8MARE”). The issue can allow an…

Read more >

cve-2026-21858

New Year Threat Brief: 6 Key Attack Paths to Watch in 2026

As we kick off the new year, it’s crucial for technology and security leaders to understand the top cyber attack paths that threaten their organizations.…

Read more >

cyber threats in 2026
Under Cyber Attack?

Fill out the form and we will contact you immediately.