CVE-2026-19251 | Ultimate Member Plugin up to 2.12.x on WordPress Profile Activity information disclosure
A vulnerability classified as problematic has been found in Ultimate Member Plugin up to 2.12.x on WordPress. The affected element is an unknown function of the component Profile Activity. Performing a manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2026-19251. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.