VYPR

Ultimatemember

by WordPress

Source repositories

CVEs (64)

  • CVE-2024-2123HigMar 13, 2024
    risk 0.42cvss 7.2epss 0.27

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input…

  • CVE-2022-1208MedJun 13, 2022
    risk 0.42cvss 6.4epss 0.01

    The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding…

  • CVE-2015-9304MedAug 12, 2019
    risk 0.40cvss 6.1epss 0.01

    The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.

  • CVE-2018-17866MedOct 9, 2018
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or…

  • CVE-2018-13136MedJul 4, 2018
    risk 0.40cvss 6.1epss 0.01

    The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.

  • CVE-2018-6944MedFeb 16, 2018
    risk 0.40cvss 6.1epss 0.01

    core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.

  • CVE-2018-6943MedFeb 16, 2018
    risk 0.40cvss 6.1epss 0.01

    core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.

  • CVE-2020-37169MedMay 13, 2026
    risk 0.36cvss 5.5epss 0.00

    WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to…

  • CVE-2025-47691MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3.

  • CVE-2026-18547MedAug 25, 2026
    risk 0.35cvss 6.4epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) in all versions up…

  • CVE-2025-15064MedApr 4, 2026
    risk 0.35cvss 6.4epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due to insufficient…

  • CVE-2025-13217MedDec 17, 2025
    risk 0.35cvss 6.4epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2.11.0. This is due to…

  • CVE-2024-8519MedOct 4, 2024
    risk 0.35cvss 6.4epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to…

  • CVE-2021-24306MedMay 24, 2021
    risk 0.35cvss 5.4epss 0.01

    The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site…

  • CVE-2020-6859MedJan 13, 2020
    risk 0.35cvss 5.3epss 0.02

    Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to…

  • CVE-2019-14947MedAug 12, 2019
    risk 0.35cvss 5.4epss 0.01

    The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.

  • CVE-2019-14946MedAug 12, 2019
    risk 0.35cvss 5.4epss 0.01

    The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.

  • CVE-2019-14945MedAug 12, 2019
    risk 0.35cvss 5.4epss 0.01

    The ultimate-member plugin before 2.0.54 for WordPress has XSS.

  • CVE-2025-12492MedDec 20, 2025
    risk 0.34cvss 5.3epss 0.01

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due…

  • CVE-2026-1404MedFeb 18, 2026
    risk 0.33cvss 6.1epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including,…