A critical unauthenticated SQL injection flaw, tracked as CVE-2024-1071, was disclosed and patched in the Ultimate Member WordPress plugin. The vulnerability affects versions 2.1.3 through 2.8.2 and carries a CVSS 9.8 rating. According to the reports, the issue stems from insufficient sanitization of a user-supplied parameter, allowing attackers to append malicious SQL queries to existing prepared statements and potentially access sensitive information without logging in.
The exposure is especially relevant for sites with the "Enable custom table for usermeta" setting turned on. Affected organizations were urged to update immediately to version 2.8.3 or later and review WordPress environments for signs of unauthorized access or unexpected changes. One report also noted that a $2,063 bug bounty was awarded for the finding, underscoring the severity and exploitability of the flaw.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The Ultimate Member WordPress plugin fixed a critical unauthenticated SQL injection vulnerability, CVE-2024-1071, in version 2.8.3. The flaw affected versions 2.1.3 through 2.8.2 and could allow attackers to access sensitive information on sites with the custom usermeta table setting enabled.
On 2024-03-04, CSIRT.SK published an alert about CVE-2024-1071, describing it as a critical SQL injection vulnerability with a CVSS score of 9.8 in the Ultimate Member WordPress plugin. The advisory recommended updating immediately to version 2.8.3 or later and reviewing sites for signs of unauthorized access or changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.