plugin

Indeed Membership Pro Vulnerabilities

29 known security issues reported for the Indeed Membership Pro WordPress plugin. Most recent disclosed Mar 23, 2026.

3 critical 4 high 3 medium

Running Indeed Membership Pro on your site? Check whether your installed version is affected.

Scan your site free

Indeed Membership Pro <= 13.7 - Missing Authorization

medium

The Indeed Membership Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 13.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 13.7
Fixed in:
13.7.1
Disclosed:
Mar 23, 2026

CVE-2026-25357 on NVD →

Ultimate Membership Pro [indeed-membership-pro] >= 7.3 - < 8.6.1

unknown

[en] The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.

Affected:
7.3 – 8.6.1
Fixed in:
8.6.1
Disclosed:
Oct 16, 2024

CVE-2020-36832 on NVD →

Ultimate Membership Pro [indeed-membership-pro] < 8.6.1

unknown

[en] The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying se...

Affected:
up to 8.6.1
Fixed in:
8.6.1
Disclosed:
Oct 16, 2024

CVE-2020-36833 on NVD →

Ultimate Membership Pro [indeed-membership-pro] < 12.8

unknown

[en] Improper Privilege Management vulnerability in azzaroco Ultimate Membership Pro allows Privilege Escalation.This issue affects Ultimate Membership Pro: from n/a through 12.6.

Affected:
up to 12.8
Fixed in:
12.8
Disclosed:
Aug 19, 2024

CVE-2024-43240 on NVD →

Ultimate Membership Pro [indeed-membership-pro] < 12.8

unknown

[en] Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro allows Object Injection.This issue affects Ultimate Membership Pro: from n/a through 12.6.

Affected:
up to 12.8
Fixed in:
12.8
Disclosed:
Aug 19, 2024

CVE-2024-43242 on NVD →

Ultimate Membership Pro [indeed-membership-pro] < 12.8

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro allows Reflected XSS.This issue affects Ultimate Membership Pro: from n/a through 12.6.

Affected:
up to 12.8
Fixed in:
12.8
Disclosed:
Aug 18, 2024

CVE-2024-43241 on NVD →

Indeed Membership Pro <= 12.7 - Unauthenticated Privilege Escalation

critical

The Indeed Membership Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 12.7. This is due to the plugin not properly restricting access to functionality that allows privilege assignment. This makes it possible for unauthenticated attackers to gain access to accounts th...

CVSS:
9.8
Affected:
up to 12.7
Fixed in:
12.8
Disclosed:
Aug 12, 2024

CVE-2024-43240 on NVD →

Indeed Membership Pro <= 12.7 - Unauthenticated PHP Object Injection

high

The Indeed Membership Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 12.7 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is...

CVSS:
8.1
Affected:
up to 12.7
Fixed in:
12.8
Disclosed:
Aug 12, 2024

CVE-2024-43242 on NVD →

Indeed Membership Pro <= 12.7 - Reflected Cross-Site Scripting

medium

The Indeed Membership Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 12.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...

CVSS:
6.1
Affected:
up to 12.7
Fixed in:
12.8
Disclosed:
Aug 12, 2024

CVE-2024-43241 on NVD →

Ultimate Membership Pro <= 8.6 - Cross-Site Request Forgery

high

The Ultimate Membership Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.6. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to create, modify, or delete user accounts, including acco...

CVSS:
8.8
Affected:
up to 8.7
Fixed in:
8.7
Disclosed:
Feb 24, 2020

Ultimate Membership Pro <= 8.6.1 - Cross-Site Request Forgery

high

The Ultimate Membership Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.6.1. This is due to missing or incorrect nonce validation on various AJAX functions. This makes it possible for unauthenticated attackers to perform a variety of tasks, such as deleting users...

CVSS:
8.8
Affected:
up to 8.6.2
Fixed in:
8.6.2
Disclosed:
Feb 24, 2020

Ultimate Membership Pro [indeed-membership-pro] < 8.6.2

unknown

Multiple Cross-Site Scripting (CSRF) vulnerabilities discovered ErwanLR in WordPress Ultimate Membership Pro premium plugin (versions <= 8.6.1).

Affected:
up to 8.6.2
Fixed in:
8.6.2
Disclosed:
Feb 24, 2020

Ultimate Membership Pro [indeed-membership-pro] < 8.7

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by ErwanLR in WordPress Ultimate Membership Pro premium plugin (versions <= 8.6).

Affected:
up to 8.7
Fixed in:
8.7
Disclosed:
Feb 24, 2020

Ultimate Membership Pro [indeed-membership-pro] < 8.7

unknown

The Ultimate Membership Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.6. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to create, modify, or delete user accounts, including acco...

Affected:
up to 8.7
Fixed in:
8.7
Disclosed:
Feb 24, 2020

Ultimate Membership Pro [indeed-membership-pro] < 8.6.2

unknown

The Ultimate Membership Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.6.1. This is due to missing or incorrect nonce validation on various AJAX functions. This makes it possible for unauthenticated attackers to perform a variety of tasks, such as deleting users...

Affected:
up to 8.6.2
Fixed in:
8.6.2
Disclosed:
Feb 24, 2020

Indeed Membership Pro 7.3 - 8.6 - Authentication Bypass

critical

The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.

CVSS:
9.8
Affected:
7.3 – 8.6.1
Fixed in:
8.6.1
Disclosed:
Feb 6, 2020

CVE-2020-36832 on NVD →

Indeed Membership Pro 7.3 - 8.6 - Missing Authorization Checks

medium

The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying setting...

CVSS:
6.3
Affected:
7.3 – 8.6
Fixed in:
8.6.1
Disclosed:
Feb 6, 2020

CVE-2020-36833 on NVD →

Ultimate Membership Pro [indeed-membership-pro] < 8.6.1

unknown

Multiple Critical Vulnerabilities found by Noman Riffat in Ultimate Membership Pro plugin (versions <= 8.6).

Affected:
up to 8.6.1
Fixed in:
8.6.1
Disclosed:
Feb 6, 2020

Ultimate Membership Pro [indeed-membership-pro] >= 7.3 - <= 8.6

unknown

The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via the username or user ID.

Affected:
7.3 – 8.6
Fixed in:
8.6
Disclosed:
Feb 6, 2020

Ultimate Membership Pro [indeed-membership-pro] >= 7.3 - <= 8.6

unknown

The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying setting...

Affected:
7.3 – 8.6
Fixed in:
8.6
Disclosed:
Feb 6, 2020

Indeed Membership Pro <= 7.5 - Arbitrary File Upload

critical

The Indeed Membership Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax-upload.php endpoint in versions up to, and including, 7.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make rem...

CVSS:
9.8
Affected:
up to 7.5
Fixed in:
7.6
Disclosed:
Feb 26, 2019

Indeed Membership Pro <= 7.5 - Remote Image File Inclusion

high

The Indeed Membership Pro plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 7.5 via the imgUrl feature. This allows unauthorized attackers to include remote files on the server, resulting in code execution.

CVSS:
8.3
Affected:
up to 7.5
Fixed in:
7.6
Disclosed:
Feb 26, 2019

Ultimate Membership Pro [indeed-membership-pro] < 7.6

unknown

The Indeed Membership Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax-upload.php endpoint in versions up to, and including, 7.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make rem...

Affected:
up to 7.6
Fixed in:
7.6
Disclosed:
Feb 26, 2019

Ultimate Membership Pro [indeed-membership-pro] < 7.6

unknown

The Indeed Membership Pro plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 7.5 via the imgUrl feature. This allows unauthorized attackers to include remote files on the server, resulting in code execution.

Affected:
up to 7.6
Fixed in:
7.6
Disclosed:
Feb 26, 2019

Ultimate Membership Pro [indeed-membership-pro] < 7.6

unknown

In addition to cropping/rotating/resizing an image of your choosing, you can abuse the imgUrl feature on versions that it&#039;s available on (7.4.2+ at least) to make an HTTP request to any site you want. For example, by having it connect to a site you control, you can determine the IP address of the origin even when...

Affected:
up to 7.6
Fixed in:
7.6

Ultimate Membership Pro [indeed-membership-pro] < 7.6

unknown

The ajax-upload.php endpoint doesn&#039;t check for the current user&#039;s capabilities (or that they are even logged in), so we can do a few things we shouldn&#039;t be able to do: Without any credentials, you can simply POST the image file in the field ihc_file and it&#039;ll store it for you: ~$ curl -F &quot...

Affected:
up to 7.6
Fixed in:
7.6

Ultimate Membership Pro [indeed-membership-pro] < 8.6.1

unknown

Multiple Critical Vulnerabilities found in Ultimate Membership Pro could leads to Authenticated (using a low privilege account, such as subscriber) Remote Code Execution on default Installation, as well as PII disclosure (such as emails, IP addresses, hashed passwords, usernames, User-Agent and so on), due to lack of a...

Affected:
up to 8.6.1
Fixed in:
8.6.1

Ultimate Membership Pro [indeed-membership-pro] < 8.7

unknown

While confirming the issues from https://wpvulndb.com/vulnerabilities/10086 have been remediated, two CSRF issues were identified, allowing attackers to make logged in administrator delete arbitrary accounts, as well as create a new administrator account. Other CSRF may be present but haven&#039;t been checked. Fe...

Affected:
up to 8.7
Fixed in:
8.7

Ultimate Membership Pro [indeed-membership-pro] < 8.6.2

unknown

Version 8.6.1 attempted fo fix multiple critical issues (mainly lack of authorisation checks, allowing low privileges users to call the admin functions of the plugin, leading to PII disclosure and login bypasses). However, the fixes were not sufficient: - An indeedIsAdmin() check was added to all AJAX calls for auth...

Affected:
up to 8.6.2
Fixed in:
8.6.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database