Ultimatemember
Source repositories
CVEs (40)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-8519 | Med | 0.35 | 6.4 | 0.00 | Oct 4, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to… | ||
| CVE-2021-24306 | Med | 0.35 | 5.4 | 0.01 | May 24, 2021 | The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site… | ||
| CVE-2019-14947 | Med | 0.35 | 5.4 | 0.01 | Aug 12, 2019 | The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade. | ||
| CVE-2019-14946 | Med | 0.35 | 5.4 | 0.01 | Aug 12, 2019 | The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations. | ||
| CVE-2019-14945 | Med | 0.35 | 5.4 | 0.01 | Aug 12, 2019 | The ultimate-member plugin before 2.0.54 for WordPress has XSS. | ||
| CVE-2018-20965 | Med | 0.33 | 6.1 | 0.01 | Aug 12, 2019 | The ultimate-member plugin before 2.0.4 for WordPress has XSS. | ||
| CVE-2016-10872 | Med | 0.33 | 6.1 | 0.01 | Aug 12, 2019 | The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form. | ||
| CVE-2024-2765 | Med | 0.28 | 5.4 | 0.01 | May 2, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to… | ||
| CVE-2023-31216 | Med | 0.28 | 4.3 | 0.00 | Jul 17, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions. | ||
| CVE-2022-3361 | Med | 0.28 | 4.3 | 0.02 | Nov 29, 2022 | The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply… | ||
| CVE-2022-1209 | Med | 0.28 | 4.3 | 0.01 | May 10, 2022 | The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1. | ||
| CVE-2020-36170 | Med | 0.28 | 5.3 | 0.01 | Jan 6, 2021 | The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms. | ||
| CVE-2019-10271 | Med | 0.28 | 4.3 | 0.01 | Jun 24, 2019 | An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures… | ||
| CVE-2018-0585 | Med | 0.28 | 5.4 | 0.01 | May 14, 2018 | Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2024-12276 | Med | 0.27 | 5.3 | 0.00 | Feb 21, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the… | ||
| CVE-2025-0318 | Med | 0.27 | 5.3 | 0.00 | Jan 18, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This… | ||
| CVE-2024-8520 | Med | 0.27 | 5.3 | 0.00 | Oct 4, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation… | ||
| CVE-2024-10528 | Med | 0.21 | 4.3 | 0.01 | Nov 21, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and… | ||
| CVE-2022-3966 | Med | 0.00 | 4.3 | 0.01 | Nov 13, 2022 | A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. The manipulation of the argument tpl leads to… | ||
| CVE-2020-6859 | Med | 0.00 | 5.3 | 0.02 | Jan 13, 2020 | Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to… |
- risk 0.35cvss 6.4epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to…
- risk 0.35cvss 5.4epss 0.01
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site…
- risk 0.35cvss 5.4epss 0.01
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
- risk 0.35cvss 5.4epss 0.01
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
- risk 0.35cvss 5.4epss 0.01
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
- risk 0.33cvss 6.1epss 0.01
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
- risk 0.33cvss 6.1epss 0.01
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
- risk 0.28cvss 5.4epss 0.01
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to…
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.
- risk 0.28cvss 4.3epss 0.02
The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply…
- risk 0.28cvss 4.3epss 0.01
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
- risk 0.28cvss 5.3epss 0.01
The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures…
- risk 0.28cvss 5.4epss 0.01
Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.27cvss 5.3epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the…
- risk 0.27cvss 5.3epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This…
- risk 0.27cvss 5.3epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation…
- risk 0.21cvss 4.3epss 0.01
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and…
- risk 0.00cvss 4.3epss 0.01
A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. The manipulation of the argument tpl leads to…
- risk 0.00cvss 5.3epss 0.02
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to…
Page 2 of 2