CVE-2026-4248 | ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress usermeta:password_reset_link improper authorization (EUVD-2026-16901)
A vulnerability classified as critical has been found in ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress. This affects an unknown part. The manipulation of the argument usermeta:password_reset_link leads to improper authorization.
This vulnerability is traded as CVE-2026-4248. It is possible to initiate the attack remotely. There is no exploit available.