VYPR

Ultimatemember

by Ultimatemember

Source repositories

CVEs (40)

  • CVE-2024-8519MedOct 4, 2024
    risk 0.35cvss 6.4epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to…

  • CVE-2021-24306MedMay 24, 2021
    risk 0.35cvss 5.4epss 0.01

    The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site…

  • CVE-2019-14947MedAug 12, 2019
    risk 0.35cvss 5.4epss 0.01

    The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.

  • CVE-2019-14946MedAug 12, 2019
    risk 0.35cvss 5.4epss 0.01

    The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.

  • CVE-2019-14945MedAug 12, 2019
    risk 0.35cvss 5.4epss 0.01

    The ultimate-member plugin before 2.0.54 for WordPress has XSS.

  • CVE-2018-20965MedAug 12, 2019
    risk 0.33cvss 6.1epss 0.01

    The ultimate-member plugin before 2.0.4 for WordPress has XSS.

  • CVE-2016-10872MedAug 12, 2019
    risk 0.33cvss 6.1epss 0.01

    The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.

  • CVE-2024-2765MedMay 2, 2024
    risk 0.28cvss 5.4epss 0.01

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to…

  • CVE-2023-31216MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.

  • CVE-2022-3361MedNov 29, 2022
    risk 0.28cvss 4.3epss 0.02

    The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply…

  • CVE-2022-1209MedMay 10, 2022
    risk 0.28cvss 4.3epss 0.01

    The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.

  • CVE-2020-36170MedJan 6, 2021
    risk 0.28cvss 5.3epss 0.01

    The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.

  • CVE-2019-10271MedJun 24, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures…

  • CVE-2018-0585MedMay 14, 2018
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2024-12276MedFeb 21, 2025
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the…

  • CVE-2025-0318MedJan 18, 2025
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This…

  • CVE-2024-8520MedOct 4, 2024
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation…

  • CVE-2024-10528MedNov 21, 2024
    risk 0.21cvss 4.3epss 0.01

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and…

  • CVE-2022-3966MedNov 13, 2022
    risk 0.00cvss 4.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/class-shortcodes.php of the component Template Handler. The manipulation of the argument tpl leads to…

  • CVE-2020-6859MedJan 13, 2020
    risk 0.00cvss 5.3epss 0.02

    Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to…

Page 2 of 2