Ultimate Member Widgets for Elementor <= 2.3 - Unauthenticated Information Exposure
medium
The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.3
- Fixed in:
- 2.4
- Disclosed:
- Nov 27, 2025
CVE-2025-66116 on NVD →
Ultimate Member Widgets for Elementor <= 2.3 - Missing Authorization to Unauthenticated Information Exposure
medium
The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_filter_users function in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to extract partial...
- CVSS:
- 5.3
- Affected:
- up to 2.3
- Fixed in:
- 2.4
- Disclosed:
- Nov 19, 2025
CVE-2025-12778 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database