Ultimatemember
by WordPress
Source repositories
CVEs (64)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-2123 | Hig | 0.42 | 7.2 | 0.27 | Mar 13, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input… | ||
| CVE-2022-1208 | Med | 0.42 | 6.4 | 0.01 | Jun 13, 2022 | The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding… | ||
| CVE-2015-9304 | Med | 0.40 | 6.1 | 0.01 | Aug 12, 2019 | The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input. | ||
| CVE-2018-17866 | Med | 0.40 | 6.1 | 0.02 | Oct 9, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or… | ||
| CVE-2018-13136 | Med | 0.40 | 6.1 | 0.01 | Jul 4, 2018 | The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen. | ||
| CVE-2018-6944 | Med | 0.40 | 6.1 | 0.01 | Feb 16, 2018 | core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable. | ||
| CVE-2018-6943 | Med | 0.40 | 6.1 | 0.01 | Feb 16, 2018 | core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable. | ||
| CVE-2020-37169 | Med | 0.36 | 5.5 | 0.00 | May 13, 2026 | WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to… | ||
| CVE-2025-47691 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3. | ||
| CVE-2026-18547 | Med | 0.35 | 6.4 | 0.00 | Aug 25, 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) in all versions up… | ||
| CVE-2025-15064 | Med | 0.35 | 6.4 | 0.00 | Apr 4, 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due to insufficient… | ||
| CVE-2025-13217 | Med | 0.35 | 6.4 | 0.00 | Dec 17, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2.11.0. This is due to… | ||
| CVE-2024-8519 | Med | 0.35 | 6.4 | 0.00 | Oct 4, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to… | ||
| CVE-2021-24306 | Med | 0.35 | 5.4 | 0.01 | May 24, 2021 | The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site… | ||
| CVE-2020-6859 | Med | 0.35 | 5.3 | 0.02 | Jan 13, 2020 | Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to… | ||
| CVE-2019-14947 | Med | 0.35 | 5.4 | 0.01 | Aug 12, 2019 | The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade. | ||
| CVE-2019-14946 | Med | 0.35 | 5.4 | 0.01 | Aug 12, 2019 | The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations. | ||
| CVE-2019-14945 | Med | 0.35 | 5.4 | 0.01 | Aug 12, 2019 | The ultimate-member plugin before 2.0.54 for WordPress has XSS. | ||
| CVE-2025-12492 | Med | 0.34 | 5.3 | 0.01 | Dec 20, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due… | ||
| CVE-2026-1404 | Med | 0.33 | 6.1 | 0.00 | Feb 18, 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including,… |
- risk 0.42cvss 7.2epss 0.27
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input…
- risk 0.42cvss 6.4epss 0.01
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding…
- risk 0.40cvss 6.1epss 0.01
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
- risk 0.40cvss 6.1epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or…
- risk 0.40cvss 6.1epss 0.01
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
- risk 0.40cvss 6.1epss 0.01
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
- risk 0.40cvss 6.1epss 0.01
core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
- risk 0.36cvss 5.5epss 0.00
WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to…
- risk 0.36cvss 5.5epss 0.00
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3.
- risk 0.35cvss 6.4epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) in all versions up…
- risk 0.35cvss 6.4epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due to insufficient…
- risk 0.35cvss 6.4epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2.11.0. This is due to…
- risk 0.35cvss 6.4epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to…
- risk 0.35cvss 5.4epss 0.01
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site…
- risk 0.35cvss 5.3epss 0.02
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to…
- risk 0.35cvss 5.4epss 0.01
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
- risk 0.35cvss 5.4epss 0.01
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
- risk 0.35cvss 5.4epss 0.01
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
- risk 0.34cvss 5.3epss 0.01
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due…
- risk 0.33cvss 6.1epss 0.00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including,…
Page 2 of 4