VYPR

Ultimatemember

by WordPress

Source repositories

CVEs (63)

  • CVE-2016-10872MedAug 12, 2019
    risk 0.33cvss 6.1epss 0.01

    The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.

  • CVE-2015-8354MedSep 11, 2017
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.

  • CVE-2018-10234MedApr 23, 2018
    risk 0.31cvss 4.8epss 0.01

    Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account page.

  • CVE-2024-2765MedMay 2, 2024
    risk 0.28cvss 5.4epss 0.01

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to…

  • CVE-2023-31216MedJul 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.

  • CVE-2022-3361MedNov 29, 2022
    risk 0.28cvss 4.3epss 0.03

    The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply…

  • CVE-2022-1209MedMay 10, 2022
    risk 0.28cvss 4.3epss 0.01

    The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.

  • CVE-2020-36170MedJan 6, 2021
    risk 0.28cvss 5.3epss 0.01

    The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.

  • CVE-2019-10271MedJun 24, 2019
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures…

  • CVE-2018-0590MedMay 14, 2018
    risk 0.28cvss 4.3epss 0.01

    Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.

  • CVE-2018-0589MedMay 14, 2018
    risk 0.28cvss 4.3epss 0.01

    Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.

  • CVE-2018-0587MedMay 14, 2018
    risk 0.28cvss 4.3epss 0.01

    Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.

  • CVE-2018-0586MedMay 14, 2018
    risk 0.28cvss 4.3epss 0.02

    Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.

  • CVE-2018-0585MedMay 14, 2018
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2026-19251MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting…

  • CVE-2024-12276MedFeb 21, 2025
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the…

  • CVE-2025-0318MedJan 18, 2025
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This…

  • CVE-2024-8520MedOct 4, 2024
    risk 0.27cvss 5.3epss 0.00

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation…

  • CVE-2025-14081MedDec 17, 2025
    risk 0.21cvss 4.3epss 0.00

    The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in the allowed fields list before the `required_perm` check is…

  • CVE-2024-10528MedNov 21, 2024
    risk 0.21cvss 4.3epss 0.01

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and…