cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forultimate-member ultimate-member

Direction: ascending
Jun 07, 2024

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2020-36155

CVE, Research URL

CVE-2020-36155

Date
Jan 04, 2021
Research Description
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access.
Affected versions
max 2.1.12.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2021-24306

CVE, Research URL

CVE-2021-24306

Date
May 24, 2021
Research Description
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site Scripting issue. Knowledge of the targeted username is required to exploit this, and attackers would then need to make the related logged in user open a malicious link.
Affected versions
max 2.1.20.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2020-36157

CVE, Research URL

CVE-2020-36157

Date
Jan 04, 2021
Research Description
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role parameter that could be supplied during the registration process, an attacker could supply the role parameter with a WordPress capability (or any custom Ultimate Member role) and effectively be granted those privileges.
Affected versions
max 2.1.12.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2020-36156

CVE, Research URL

CVE-2020-36156

Date
Jan 04, 2021
Research Description
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to any role (e.g., Administrator) during a profile update, and effectively escalate their privileges.
Affected versions
max 2.1.12.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2020-6859

CVE, Research URL

CVE-2020-6859

Date
Jan 13, 2020
Research Description
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image.
Affected versions
max 2.1.3.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2019-10270

CVE, Research URL

CVE-2019-10270

Date
Jun 21, 2019
Research Description
An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id parameter) to reset the password of another user. One only needs to know the user_id, which is publicly available. One just has to intercept the password modification request and modify user_id. It is possible to modify the passwords for any users or admin WordPress Ultimate Members. This could lead to account compromise and privilege escalation.
Affected versions
max 2.0.40.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2019-10673

CVE, Research URL

CVE-2019-10673

Date
Apr 03, 2019
Research Description
A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator profile, and then the attacker is able to reset the administrator password using the WordPress "password forget" form.
Affected versions
max 2.0.40.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-0587

CVE, Research URL

CVE-2018-0587

Date
May 14, 2018
Research Description
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
Affected versions
max 2.0.4.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-17866

CVE, Research URL

CVE-2018-17866

Date
Oct 10, 2018
Research Description
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.
Affected versions
max 2.0.28.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-0589

CVE, Research URL

CVE-2018-0589

Date
May 14, 2018
Research Description
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.
Affected versions
max 2.0.4.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-0588

CVE, Research URL

CVE-2018-0588

Date
May 14, 2018
Research Description
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
Affected versions
max 2.0.40.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-0586

CVE, Research URL

CVE-2018-0586

Date
May 14, 2018
Research Description
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.
Affected versions
max 2.0.4.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-10234

CVE, Research URL

CVE-2018-10234

Date
Apr 23, 2018
Research Description
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account page.
Affected versions
max 2.0.11.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2019-10271

CVE, Research URL

CVE-2019-10271

Date
Jun 25, 2019
Research Description
An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures of privileged users. To perform such a modification, one first needs to (for example) intercept an upload-picture request and modify the user_id parameter.
Affected versions
max 2.0.40.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-0590

CVE, Research URL

CVE-2018-0590

Date
May 14, 2018
Research Description
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.
Affected versions
max 2.0.4.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-0585

CVE, Research URL

CVE-2018-0585

Date
May 14, 2018
Research Description
Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected versions
max 2.0.4.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-10233

CVE, Research URL

CVE-2018-10233

Date
Apr 23, 2018
Research Description
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
Affected versions
max 2.0.7.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-6943

CVE, Research URL

CVE-2018-6943

Date
Feb 16, 2018
Research Description
core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
Affected versions
max 2.0.4.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2018-6944

CVE, Research URL

CVE-2018-6944

Date
Feb 16, 2018
Research Description
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
Affected versions
max 2.0.4.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2022-1209

CVE, Research URL

CVE-2022-1209

Date
May 11, 2022
Research Description
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
Affected versions
max 2.3.2.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2022-1208

CVE, Research URL

CVE-2022-1208

Date
Jun 13, 2022
Research Description
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding that is reflected back on the page. This affects versions up to, and including, 2.3.2. Please note this issue was only partially fixed in version 2.3.2.
Affected versions
Min 1.2.98, max 2.4.0.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2015-8354

CVE, Research URL

CVE-2015-8354

Date
Sep 12, 2017
Research Description
Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.
Affected versions
max 1.3.29.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2022-3383

CVE, Research URL

CVE-2022-3383

Date
Nov 30, 2022
Research Description
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). This makes it possible for authenticated attackers, with administrative capabilities, to execute code on the server.
Affected versions
max 2.5.1.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2022-3384

CVE, Research URL

CVE-2022-3384

Date
Nov 30, 2022
Research Description
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP functions like phpinfo(); since user supplied parameters are not passed through the function. This makes it possible for authenticated attackers, with administrative privileges, to execute code on the server.
Affected versions
max 2.5.1.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2022-3361

CVE, Research URL

CVE-2022-3361

Date
Nov 30, 2022
Research Description
The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply arbitrary paths using traversal (../../) to access and include files outside of the intended directory. If an attacker can successfully upload a php file then remote code execution via inclusion may also be possible. Note: for users with less than administrative capabilities, /wp-admin access needs to be enabled for that user in order for this to be exploitable by those users.
Affected versions
max 2.5.1.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2023-3460

CVE, Research URL

CVE-2023-3460

Date
Jul 04, 2023
Research Description
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.
Affected versions
max 2.6.7.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2024-2123

CVE, Research URL

CVE-2024-2123

Date
Mar 13, 2024
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.8.4.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2024-1071

CVE, Research URL

CVE-2024-1071

Date
Mar 13, 2024
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 2.8.3.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2024-2765

CVE, Research URL

CVE-2024-2765

Date
May 02, 2024
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.8.5.
Status
vulnerable
Oct 04, 2024

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2024-8520

CVE, Research URL

CVE-2024-8520

Date
Oct 04, 2024
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the admin_init or user_action_hook function. This makes it possible for unauthenticated attackers to modify a users membership status via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.8.7.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2024-8519

CVE, Research URL

CVE-2024-8519

Date
Oct 04, 2024
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.8.7.
Status
vulnerable
Nov 22, 2024

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2024-10528

CVE, Research URL

CVE-2024-10528

Date
Nov 21, 2024
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and ajax_resize_image() functions in all versions up to, and including, 2.8.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the profile pictures of other users.
Affected versions
max 2.9.0.
Status
vulnerable
Jan 18, 2025

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2025-0308

CVE, Research URL

CVE-2025-0308

Date
Jan 18, 2025
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 2.9.2.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2025-0318

CVE, Research URL

CVE-2025-0318

Date
Jan 18, 2025
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated attackers to exfiltrate data from wp_usermeta table.
Affected versions
max 2.9.2.
Status
vulnerable
Feb 22, 2025

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2024-12276

CVE, Research URL

CVE-2024-12276

Date
Feb 21, 2025
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with access to upload files and manage filenames through a third-party plugin like a File Manager, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The risk of this vulnerability is very minimal as it requires a user to be able to manipulate filenames in order to successfully exploit.
Affected versions
max 2.10.0.
Status
vulnerable
Mar 05, 2025

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2025-1702

CVE, Research URL

CVE-2025-1702

Date
Mar 05, 2025
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 2.10.1.
Status
vulnerable
Jan 28, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2025-13217

CVE, Research URL

CVE-2025-13217

Date
Dec 18, 2025
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escaping on user-supplied YouTube video URLs in the `um_profile_field_filter_hook__youtube_video()` function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses the injected user's profile page.
Affected versions
max 2.11.1.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2025-14081

CVE, Research URL

CVE-2025-14081

Date
Dec 18, 2025
Research Description
The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in the allowed fields list before the `required_perm` check is applied during rendering. This makes it possible for authenticated attackers with Subscriber-level access to modify their profile privacy settings (e.g., setting profile to "Only me") via direct parameter manipulation, even when the administrator has explicitly disabled the option for their role.
Affected versions
max 2.11.1.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2025-13220

CVE, Research URL

CVE-2025-13220

Date
Dec 21, 2025
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes in all versions up to, and including, 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.11.1.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2025-12492

CVE, Research URL

CVE-2025-12492

Date
Dec 20, 2025
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictable low-entropy token (5 hex characters derived from md5 of post ID) to identify member directories and insufficient authorization checks on the unauthenticated AJAX endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, display names, user roles (including administrator accounts), profile URLs, and user IDs by enumerating predictable directory_id values or brute-forcing the small 16^5 token space.
Affected versions
max 2.11.1.
Status
vulnerable
Apr 13, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2025-15064

CVE, Research URL

CVE-2025-15064

Date
Apr 04, 2026
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is only exploitable when "HTML support for user description" is enabled in Ultimate Member settings.
Affected versions
max 2.11.2.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2026-4248

CVE, Research URL

CVE-2026-4248

Date
Mar 28, 2026
Research Description
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid password reset token for the currently logged-in user viewing the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to craft a malicious pending post that, when previewed by an Administrator, generates a password reset token for the Administrator and exfiltrates it to an attacker-controlled server, leading to full account takeover.
Affected versions
max 2.11.3.
Status
vulnerable
Apr 14, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2026-1404

CVE, Research URL

CVE-2026-1404

Date
Feb 18, 2026
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.11.2.
Status
vulnerable
May 15, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2020-37169

CVE, Research URL

CVE-2020-37169

Date
May 13, 2026
Research Description
WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP files from the packages directory and execute arbitrary code.
Affected versions
max 2.1.3.
Status
vulnerable
Jun 13, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin # CVE-2025-47691

CVE, Research URL

CVE-2025-47691

Date
May 07, 2025
Research Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3.
Affected versions
max 2.10.4.
Status
vulnerable
Jun 16, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # ac43741987f0c1740eefdaf7e33e8eaf26636c26

Date
Aug 09, 2018
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.22 WordPress Ultimate Member plugin <= 2.0.21 - Unauthenticated Arbitrary File Upload vulnerability Unauthenticated Arbitrary File Upload vulnerability found in WordPress Ultimate Member plugin (versions <= 2.0.21).
Affected versions
max 2.0.22.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 33f8d8cbc9a6ab0eb321f958638637976085d878

Date
Dec 06, 2016
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.3.76 WordPress Ultimate Member Plugin <= 1.3.75 - Unauthenticated Change Passwords This plugin is prone to an unauthenticated change passwords vulnerability. Update the plugin.
Affected versions
max 1.3.76.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 1c50ab93c4d4492b3b6a058f50ccc1a8a9e204a5

Date
Jul 10, 2016
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.3.65 WordPress Ultimate Member Plugin <= 1.3.64 - Local File Inclusion This plugin is prone to a PHP file inclusion vulnerability. Update the plugin.
Affected versions
max 1.3.65.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # a9e0185b022f1f539430e4e3a9e44bd19423e5c8

Date
Jun 18, 2015
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.2.995 WordPress Ultimate Member Plugin <= 1.2.994 - Cross Site Scripting This plugin is prone to a cross site scripting vulnerability, because attackers load data from a location. After that, data from that location is output on the target domain and JavaScript is executed under the context of the current user of the site. Update the plugin.
Affected versions
max 1.2.995.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 18115d096029483854e2d599e1202afb74ef3962

Date
Dec 02, 2015
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.3.29 WordPress Ultimate Member Plugin <= 1.3.28 - Reflected Cross Site Scripting Because of this vulnerability, attackers cat steal administrator's cookies, credentials and browser history and modify web page content to perform phishing attacks. Update the plugin.
Affected versions
max 1.3.29.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 0ac2730b74a5d6e6d8b47f45b891640ad075ee99

Date
May 16, 2019
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.46 WordPress Ultimate Member plugin <= 2.0.45 - Multiple vulnerabilities Multiple vulnerabilities found by Antony Garand (Sucuri team) in WordPress Ultimate Member plugin (versions <= 2.0.45).
Affected versions
max 2.0.46.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # f37acb49bfea40595786c2f64966390a02868d57

Date
Nov 27, 2018
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.33 WordPress Ultimate Member plugin <= 2.0.32 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found in WordPress Ultimate Member plugin (versions <= 2.0.32).
Affected versions
max 2.0.33.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # ed803776620f3f7034cc4dca6b21b0f443848400

Date
Nov 09, 2020
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.1.12 WordPress Ultimate Member plugin <= 2.1.11 - Unauthenticated/Authenticated Privilege Escalation Unauthenticated Privilege Escalation via User Meta vulnerability found by Chloe Chamberland in WordPress Ultimate Member plugin (versions <= 2.1.11).
Affected versions
max 2.1.12.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 6e258728caeed0fd59e4954753924bb80c732e25

Date
Jul 13, 2019
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.52 WordPress Ultimate Member plugin <= 2.0.51 - Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities found by m0ns7er in WordPress Ultimate Member plugin (versions <= 2.0.51).
Affected versions
max 2.0.52.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 24caf2fe8b9ccd0bd73a98de1321d863aaac4e92

Date
Aug 28, 2018
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.22 WordPress Ultimate Member plugin <= 2.0.21 - Authenticated Cross-Site Scripting (XSS) vulnerability Authenticated Cross-Site Scripting (XSS) vulnerability found in WordPress Ultimate Member plugin (versions <= 2.0.21).
Affected versions
max 2.0.22.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 97823f41-7614-420e-81b8-9e735e4c203f

Date
-
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.1.7 Ultimate Member &lt; 2.1.7 - Unauthenticated Open Redirect The Ultimate Member WordPress plugin was vulnerable to an Unauthenticated Open Redirect vulnerability, affecting the registration and login pages where the &quot;redirect_to&quot; GET parameter was used.
Affected versions
max 2.1.7.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 5eabcb2a-c27a-4b33-9d07-6507e0007c50

Date
-
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.0.84 Ultimate Member &lt;= 1.0.78 - Multiple Vulnerabilities Ultimate Member Plugin version 1.0.78 has several security vulnerabilities that allow unauthenticated users to delete and upload files, which can ultimately lead to remote code execution.
Affected versions
max 1.0.84.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 0931056f-f13c-4eeb-874b-e708895fcb26

Date
-
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.22 Ultimate Member &lt; 2.0.22 - Authenticated Cross-Site Scripting (XSS) The Ultimate Member &ndash; User Profile, User Registration, Login &amp; Membership Plugin WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 2.0.22.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 3b6a5da0-511d-46f7-9b55-64d771b633a7

Date
-
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] >= 1.2.98 - <= 1.2.994 Ultimate Member 1.2.98-1.2.994 - Reflected Cross-Site Scripting (XSS) The Ultimate Member plugin utilizes the Redux Framework. The Redux Framework includes a script named &lsquo;class.p.php&rsquo;, which acts as a HTTP proxy. Utilizing this script, it is possible to trigger a Reflected XSS attack, by loading data from a location controlled by the attacker. The data from this location is then output on the target domain, and as such JavaScript is executed under the context of the current user of the site.
Affected versions
Min 1.2.98, max 1.2.994.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # aa753fc0-10f3-4934-94ae-dd8d713a0190

Date
-
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.22 Ultimate Member &lt; 2.0.22 - Unauthenticated Arbitrary File Upload The Ultimate Member &ndash; User Profile, User Registration, Login &amp; Membership Plugin WordPress plugin was affected by an Unauthenticated Arbitrary File Upload security vulnerability.
Affected versions
max 2.0.22.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 017d7dc2b798babc4073058ca4dfded9a3ea0a96

Date
Jul 15, 2022
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.4.1 Ultimate Member <= 2.4.0 - Subscriber+ Stored Cross-Site Scripting The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘website’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user clicks on the username of an affected user.
Affected versions
max 2.4.1.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 3bbcfb9d-d1d4-4979-9ff2-319b17a7d487

Date
-
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.3.76 Ultimate Member &lt; 1.3.76 - Unauthenticated Change Passwords Ultimate Member versions below 1.3.76 contain a critical security issue that allows unauthenticated users to reset any users password to an arbitrary value
Affected versions
max 1.3.76.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 3ccc5483-2dd9-4925-95dd-3faa5cfdb951

Date
-
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.3.65 Ultimate Member &lt; 1.3.65 - Local File Inclusion It was discovered that Ultimate Member is vulnerable to PHP File Inclusion. In order to exploit this issue an attacker must be able to place an arbitrary PHP file on the target system. Afterwards the attacker needs to lure an authenticated admin to visit a malicious page. Through CSRF the attacker could compromise WordPress, by executing the malicious PHP file.
Affected versions
max 1.3.65.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # efcd310212d808c2eea68428b63e3dc0eed77528

Date
Mar 16, 2015
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.0.84 WordPress Ultimate Member Plugin <= 1.0.78 - Multiple Vulnerabilities Because of multiple vulnerabilities in this plugin, attackers can delete any file or upload arbitrary files. Update the plugin.
Affected versions
max 1.0.84.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 7c54f599-70c0-42ee-9bb3-bd8d8010e08d

Date
-
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.46 Ultimate Member &lt; 2.0.46 - Multiple Vulnerabilities The Ultimate Member &ndash; User Profile, User Registration, Login &amp; Membership Plugin WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.
Affected versions
max 2.0.46.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # bc772efe3ddad1ed0f539ffebff535a3938e0826

Date
Apr 17, 2017
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.3.84 Ultimate Member <= 1.3.83 - Shortcode Injection The Ultimate Member plugin for WordPress is vulnerable to Executing Arbitrary WordPress Shortcodes in versions up to, and including, 1.3.83. This is due to 'ultimatemember_frontend_modal' AJAX action allowing for the execution of the 'do_shortcode()' function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected versions
max 1.3.84.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 569894e030acbd88c54552bc45d595a9d6238385

Date
Jul 14, 2022
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.4.2 Ultimate Member <= 2.4.1 - Username Enumeration The Ultimate Member plugin for WordPress is vulnerable to Username Enumeration in versions up to, and including, 2.4.1 via the um_get_members ajax action. This allows unauthenticated attackers to obtain a list of users including user names on that site.
Affected versions
max 2.4.2.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # ca4c8a9a3738f5f6af97d7bcb1727eb8d11b02d8

Date
May 13, 2019
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.46 Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.0.45 - Arbitrary File Deletion/Read The Ultimate Member – User Profile, User Registration, Login & Membership Plugin plugin for WordPress is vulnerable to arbitrary file deletion and reading when the file upload functionality is enabled for the user profile and registration forms in versions up to, and including 2.0.45. This is due to the fact that the plugin did not perform sufficient file path validation or restrict the files that users had access to when performing a file download or deletion. This makes it possible for low-level privileged attackers to delete arbitrary files such as the wp-config.php file and ultimately achieve remote code execution.
Affected versions
max 2.0.46.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # b725e2ed5313af59fc42a3d4aef17fea598573d6

Date
Aug 08, 2018
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.22 Ultimate Member <= 2.0.21 - Arbitrary File Upload The Arbitrary File Upload plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.0.21. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Affected versions
max 2.0.22.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 856bd614de7b31bcb043318e9d931d07224d0493

Date
Jul 10, 2016
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.3.65 Ultimate Member <= 1.3.64 - Local File Inclusion The Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.64 via the 'page' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Affected versions
max 1.3.65.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 10a9c76294a67e9402488465623cc0c20aad3509

Date
Jun 18, 2015
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.2.995 Ultimate Member 1.2.98 - 1.2.997 - Reflected Cross-Site Scripting The Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in versions 1.2.98 through 1.2.997 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.2.995.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 7a13b97c177280eff3d504b4908bdefb17b23490

Date
Mar 10, 2015
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.0.84 Ultimate Member < 1.0.84 - Authorization Bypass to Arbitrary File Upload/Delete The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ultimatemember_remove_file() function in versions up to, and including, 1.0.83. This makes it possible for unauthenticated attackers to delete or upload arbitrary files.
Affected versions
max 1.0.84.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # a0c6334eb7ffd06bcdb883474f04dc0481953943

Date
Nov 27, 2018
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.33 Ultimate Member <= 2.0.32 - Cross-Site Request Forgery The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.32. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to execute arbitrary actions via forged requests granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.0.33.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # a0327b7677e3e4053aa61a4784bb26f82dcbb23b

Date
Aug 09, 2018
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.22 Ultimate Member <= 2.0.21 - Cross-Site Scripting The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.21 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 2.0.22.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # d1315e83e3a1194e7de0bcadf6b9ee46041e4b4f

Date
Dec 06, 2016
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 1.3.76 Ultimate Member <= 1.3.75 - Missing Authorization to Password Reset The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 1.3.75. This makes it possible for unauthenticated attackers to change the passwords of any user within the vulnerabilities scope.
Affected versions
max 1.3.76.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # bd5904e0ff07bbbdcd5d33770a948e713e56c451

Date
Jul 23, 2020
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.1.7 Ultimate Member <= 2.1.6 - Open Redirect The Ultimate Member plugin for WordPress is vulnerable to open redirects in versions up to, and including, 2.1.6 This is due to insufficient redirect location validation which makes it possible for unauthenticated attackers to trick victims into accessing malicious sites granted they can trick the victim into performing an action such as clicking on a link.
Affected versions
max 2.1.7.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # e2bd60906ff7a4d622dd7504dd4e4cfc9a7d1bc4

Date
May 13, 2019
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.46 Ultimate Member <= 2.0.45 - Admin+ Stored Cross-Site Scripting The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several of the plugin's form parameter in versions up to, and including,2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level capabilities to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 2.0.46.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # f0b7bac389d191b33ebe4419d9c39e0349dc2f3a

Date
May 13, 2019
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.0.46 Ultimate Member <= 2.0.45 - Low-Privileged Stored Cross-Site Scripting The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file's name from a user profile upload in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for low-level authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.0.46.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 0b1c574c20a1c7b057a6af8d49f36be74529169b

Date
Aug 09, 2023
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.6.9 WordPress Ultimate Member Plugin <= 2.6.8 is vulnerable to Cross Site Request Forgery (CSRF) Update the WordPress Ultimate Member plugin to the latest available version (at least 2.6.9). WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Ultimate Member Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 2.6.9.
Affected versions
max 2.6.9.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 56b5f631c01dbed38fd8789d29bb926ac16f435d

Date
Apr 16, 2025
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.10.2 Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability was partially patched in version 2.9.2 when initially addressing CVE-2025-0308.
Affected versions
max 2.10.2.
Status
vulnerable

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # 8121dbf5096e7ec5c00d138e665aca8de422e669

Date
Aug 08, 2023
Research Description
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin [ultimate-member] < 2.6.9 Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.6.8 - Cross-Site Request Forgery The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.8. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to invoke select functions using the 'um_admin_do_action__' hook via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.6.9.
Status
vulnerable
Jun 25, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # CVE-2026-7761

CVE, Research URL

CVE-2026-7761

Date
Jun 24, 2026
Research Description
The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.11.4. This is due to a chain of three logic bugs: (1) an MD5 hash fallback in get_directory_by_hash() that allows any post to be used as a member directory by computing SUBSTRING(MD5(post_id), 11, 5), (2) a strstr() parsing logic flaw in post_data() that allows bypassing WordPress's protected meta key restrictions by placing '_um_' anywhere in the meta key name rather than at the start, and (3) missing field name validation in build_user_card_data() that allows arbitrary field names including 'password_reset_link' to be passed to um_filtered_value(). This makes it possible for authenticated attackers with Contributor-level access and above to create a malicious post via XMLRPC with crafted meta fields, use the MD5 fallback to point the member directory AJAX handler to their post, inject 'password_reset_link' into the tagline_fields configuration, and leak live password reset URLs for all users in the member directory response, including administrators.
Affected versions
max 2.12.0.
Status
vulnerable
Jul 03, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # CVE-2026-8489

CVE, Research URL

CVE-2026-8489

Date
Jul 03, 2026
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and including, 2.11.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.12.0.
Status
vulnerable
Jul 07, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # CVE-2026-11766

CVE, Research URL

CVE-2026-11766

Date
Jul 06, 2026
Research Description
The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator, views the affected profile.
Affected versions
max 2.12.0.
Status
vulnerable
Jul 12, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # CVE-2026-15290

CVE, Research URL

CVE-2026-15290

Date
Jul 10, 2026
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability was partially patched in version 2.9.2 when initially addressing CVE-2025-0308.
Affected versions
max 2.10.2.
Status
vulnerable
Aug 01, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # CVE-2026-12251

CVE, Research URL

CVE-2026-12251

Date
Jul 31, 2026
Research Description
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a role exists and a role-selection field is present on a published registration form.
Affected versions
max 2.12.1.
Status
vulnerable
Aug 26, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin # CVE-2026-18547

CVE, Research URL

CVE-2026-18547

Date
Aug 25, 2026
Research Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the wp_kses 'templates' allowlist permits the id attribute on div elements but does not neutralize unescaped quotes within its value; when pickadate.js concatenates the stored id value into an HTML string via jQuery .html() on profile page load, the smuggled onfocus and autofocus attribute syntax breaks out of attribute context and executes as JavaScript.
Affected versions
max 2.13.0.
Status
vulnerable