How CVE-2023-3460 Works
The Ultimate Member plugin is handing out administrator accounts to anyone who fills out its registration form, and sites are already burning. CVE-2023-3460 is a critical privilege escalation flaw tracked with a CVSS v3.1 score of 9.8. It affects every version of Ultimate Member up to and including v2.6.6, and the plugin powers over 200,000 active WordPress installations.
The bug lives in the registration flow. Ultimate Member lets visitors sign up through forms you can place anywhere on a site. When a new account is created, the plugin processes user meta that comes back from the form. Attackers abuse that path to set the wp_capabilities user meta key to a value that grants administrator role, and they do it without logging in.
The vendor built a blocklist to stop users from upgrading their own capabilities. Wordfence researchers who first flagged active exploitation say bypassing that protection is trivial. The escalation is unauthenticated, so no existing account, no password spray, no brute force is needed. One crafted request to the registration endpoint is enough to mint a new admin.
Attack Evidence in the Wild
Wordfence discovered the campaign in June 2023 and published indicators as the attacks unfolded. The pattern is consistent: a new admin appears, it comes from a known malicious IP, and then plugins and themes start showing up that the site owner never installed.
The usernames keep repeating. Wordfence lists wpenginer, wpadmins, wpengine_backup, se_brutal and segs_brutal as the handles seen across compromised sites. Attackers also tie accounts to email addresses at exelica.com. Once the rogue admin exists, the payload expands; Wordfence notes new WordPress plugins and themes being installed after access is gained.
Log evidence points to a small set of source IPs. Requests to the Ultimate Member registration page are showing up from 146.70.189.245, 103.187.5.128, 103.30.11.160, 103.30.11.146 and 172.70.147.176. Those IPs are being flagged as malicious across telemetry, and their appearance in access logs together with a new admin account is a strong signal of exploitation.
The flaw is also easy to scale. Because registration forms are public, attackers can automate submissions against thousands of sites that run Ultimate Member. The plugin’s wide install base means the blast radius is large even if the individual exploit is simple.
Versions, Partial Fixes and the Real Patch
The development team first heard about the issue around the 2.6.3 release. A developer posted that work on the fixes started with 2.6.3, and that versions 2.6.4, 2.6.5 and 2.6.6 only partially close the vulnerability. The team said they were collaborating with the WPScan team to get the best result and asked users to upgrade to 2.6.6 and keep updating.
Wordfence confirmed the partial nature of those releases. Bypasses remained possible after 2.6.6, which is why the advisory kept urging caution. Quorum Cyber’s threat intelligence assessment later clarified the version boundary: all versions prior to 2.6.7 are vulnerable, and 2.6.7 is the release that fixes CVE-2023-3460.
In practice that means you should verify the installed version in WordPress > Plugins. If you see Ultimate Member below 2.6.7, the site is exposed. The fix is not a configuration tweak; it requires the patched code.
What Compromise Looks Like
You don’t need a dashboard alert to suspect a problem. Common signs line up with the IoCs Wordfence published.
New administrator accounts appear with the usernames above, often with creation timestamps clustered around a single day. Server logs show access to the Ultimate Member registration page from the five IPs listed earlier. User accounts linked to exelica.com email domains show up where you expect none. Unauthorized plugins or themes are installed, sometimes immediately after the admin account is created.
Because the initial access uses valid credentials created by the attacker, later defenses degrade. Wordfence points to data from the Blue Report 2026, which measured defenses across 338 million simulations in production environments. Once attackers hold valid credentials, only about 37% of their subsequent actions are blocked. Initial access via a manufactured admin account fundamentally undermines prevention posture, which is why the first sign matters so much.
Immediate Mitigation
Given the critical severity and the ease of exploitation, Wordfence recommends removing the Ultimate Member plugin entirely until a complete fix is in place. The firm specifically notes that even a firewall rule it developed for its clients does not cover all exploitation scenarios. Uninstalling is the only prudent action for at-risk sites that cannot patch immediately.
If you already removed the plugin, that’s not remediation, it’s just containment. A compromised site needs a full malware scan to uproot rogue admin accounts and any backdoors the attacker planted. Check Users for unfamiliar administrators, delete them, and force password resets for legitimate admins. Audit installed plugins and themes for anything added without approval, and review the registration logs for the malicious IPs.
For sites that can update, move to 2.6.7 or later as soon as it is available in your environment, then harden registration. Limit who can register, restrict registration forms to trusted referrers where feasible, and monitor new user creation with alerts. Delete any administrator accounts you don’t recognize and check logs for suspicious traffic, as Quorum Cyber advises.
The broader lesson is familiar: popular third-party plugins are a favored entry point. Ultimate Member’s user base of over 200,000 active installs made it an attractive target. Attackers are increasingly exploiting vulnerabilities in widely used plugins to gain unauthorized access, and CVE-2023-3460 is a textbook example of that trend.
Source References
- BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-exploit-zero-day-in-ultimate-member-wordpress-plugin-with-200k-installs/
- Quorum Cyber: https://www.quorumcyber.com/threat-intelligence/critical-zero-day-vulnerability-in-ultimate-member-wordpress-plugin/
- CVE Record: https://www.cve.org/CVERecord?id=CVE-2023-3460