Ultimate Member <= 2.12.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute)
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) in all versions up to, and including, 2.12.1 due to insufficient...
- CVSS:
- 6.4
- Affected:
- up to 2.12.1
- Fixed in:
- 2.13.0
- Disclosed:
- Aug 24, 2026
CVE-2026-18547 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin < 2.12.1 - Unauthenticated Privilege Escalation
high
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.12.1 (exclusive). This is due to the plugin not restricting ultimate member roles during registration. This makes it possi...
- CVSS:
- 7.3
- Affected:
- up to 2.12.1
- Fixed in:
- 2.12.1
- Disclosed:
- Aug 5, 2026
CVE-2026-12251 on NVD →
Ultimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and including, 2.11.4 due to insufficient input sanitization and output escaping. This...
- CVSS:
- 6.4
- Affected:
- up to 2.11.4
- Fixed in:
- 2.12.0
- Disclosed:
- Jul 2, 2026
CVE-2026-8489 on NVD →
Ultimate Member <= 2.11.4 - Authenticated (Contributor+) Account Takeover via Password Reset Link Disclosure
high
The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.11.4. This is due to a chain of three logic bugs: (1) an MD5 hash fallback in get_directory_by_hash() that allows any post to be used as a member directory by computing SUB...
- CVSS:
- 8.8
- Affected:
- up to 2.11.4
- Fixed in:
- 2.12.0
- Disclosed:
- Jun 23, 2026
CVE-2026-7761 on NVD →
Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. Thi...
- CVSS:
- 6.4
- Affected:
- up to 2.11.1
- Fixed in:
- 2.11.2
- Disclosed:
- Apr 3, 2026
CVE-2025-15064 on NVD →
Ultimate Member - Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag vulnerability
high
Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag vulnerability
- CVSS:
- 8
- Affected:
- up to 2.11.2
- Fixed in:
- 2.11.3
- Disclosed:
- Mar 30, 2026
Ultimate Member <= 2.11.2 - Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag
high
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid password reset token for...
- CVSS:
- 8
- Affected:
- up to 2.11.2
- Fixed in:
- 2.11.3
- Disclosed:
- Mar 27, 2026
CVE-2026-4248 on NVD →
Ultimate Member <= 2.11.1 - Reflected Cross-Site Scripting via Filter Parameters
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11.1 due to insufficient input sanitizatio...
- CVSS:
- 6.1
- Affected:
- up to 2.11.1
- Fixed in:
- 2.11.2
- Disclosed:
- Feb 17, 2026
CVE-2026-1404 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.1
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes in all versions up to, and including, 2.11.0 due to insufficient input sanitization and output e...
- Affected:
- up to 2.11.1
- Fixed in:
- 2.11.1
- Disclosed:
- Dec 21, 2025
CVE-2025-13220 on NVD →
Ultimate Member <= 2.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes in all versions up to, and including, 2.11.0 due to insufficient input sanitization and output escapi...
- CVSS:
- 6.4
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.1
- Disclosed:
- Dec 20, 2025
CVE-2025-13220 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.1
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictable low-entropy...
- Affected:
- up to 2.11.1
- Fixed in:
- 2.11.1
- Disclosed:
- Dec 20, 2025
CVE-2025-12492 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 - Unauthenticated Sensitive Information Exposure
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictable low-entropy toke...
- CVSS:
- 5.3
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.1
- Disclosed:
- Dec 19, 2025
CVE-2025-12492 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.1
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output e...
- Affected:
- up to 2.11.1
- Fixed in:
- 2.11.1
- Disclosed:
- Dec 17, 2025
CVE-2025-13217 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.1
unknown
[en] The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in the allowed fields list before the `required_perm` check is applied during rendering. This makes...
- Affected:
- up to 2.11.1
- Fixed in:
- 2.11.1
- Disclosed:
- Dec 17, 2025
CVE-2025-14081 on NVD →
Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value'
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escapi...
- CVSS:
- 6.4
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.1
- Disclosed:
- Dec 16, 2025
CVE-2025-13217 on NVD →
Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Profile Privacy Setting Bypass
medium
The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in the allowed fields list before the `required_perm` check is applied during rendering. This makes it p...
- CVSS:
- 4.3
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.1
- Disclosed:
- Dec 16, 2025
CVE-2025-14081 on NVD →
Ultimate Member <= 2.10.3 - Authenticated (Administrator+) Arbitrary Function Call
high
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Arbitrary Function Calls in all versions up to, and including, 2.10.3. This is due to the plugin not properly restricting functions that can be called. This makes it p...
- CVSS:
- 7.2
- Affected:
- up to 2.10.3
- Fixed in:
- 2.10.4
- Disclosed:
- May 7, 2025
CVE-2025-47691 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] <= 2.10.3 (unfixed)
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member allows Code Injection. This issue affects Ultimate Member: from n/a through 2.10.3.
- Affected:
- up to 2.10.3
- Fix:
- No patched version reported
- Disclosed:
- May 7, 2025
CVE-2025-47691 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection
high
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on the user supplied parameter and lack of suffi...
- CVSS:
- 7.5
- Affected:
- up to 2.10.1
- Fixed in:
- 2.10.2
- Disclosed:
- Apr 16, 2025
CVE-2026-15290 on NVD →
Ultimate Member <= 2.10.0 - Unauthenticated SQL Injection via search Parameter
high
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to insufficient escaping on the user supplied parameter and lack o...
- CVSS:
- 7.5
- Affected:
- up to 2.10.0
- Fixed in:
- 2.10.1
- Disclosed:
- Mar 4, 2025
CVE-2025-1702 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.10.0
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the user supplied parameter and lack of suffi...
- Affected:
- up to 2.10.0
- Fixed in:
- 2.10.0
- Disclosed:
- Feb 21, 2025
CVE-2024-12276 on NVD →
Ultimate Member <= 2.9.2 - Authenticated SQL Injection
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient...
- CVSS:
- 5.3
- Affected:
- up to 2.9.2
- Fixed in:
- 2.10.0
- Disclosed:
- Feb 20, 2025
CVE-2024-12276 on NVD →
Ultimate Member <= 2.9.1 - Unauthenticated SQL Injection
high
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of s...
- CVSS:
- 7.5
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 17, 2025
CVE-2025-0308 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated attacker...
- CVSS:
- 5.3
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 17, 2025
CVE-2025-0318 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.9.0
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and ajax_resize_image() functions in all versions up to, a...
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
- Disclosed:
- Nov 21, 2024
CVE-2024-10528 on NVD →
Ultimate Member <= 2.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture Update
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and ajax_resize_image() functions in all versions up to, and in...
- CVSS:
- 4.3
- Affected:
- up to 2.8.9
- Fixed in:
- 2.9.0
- Disclosed:
- Nov 20, 2024
CVE-2024-10528 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.8.7
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output...
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Oct 4, 2024
CVE-2024-8519 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.8.7
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the admin_init or user_action_hook...
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Oct 4, 2024
CVE-2024-8520 on NVD →
Ultimate Member <= 2.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output esca...
- CVSS:
- 6.4
- Affected:
- up to 2.8.6
- Fixed in:
- 2.8.7
- Disclosed:
- Oct 3, 2024
CVE-2024-8519 on NVD →
Ultimate Member <= 2.8.6 - Cross-Site Request Forgery to Membership Status Change
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the admin_init or user_action_hook func...
- CVSS:
- 5.3
- Affected:
- up to 2.8.6
- Fixed in:
- 2.8.7
- Disclosed:
- Oct 3, 2024
CVE-2024-8520 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.8.5
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output...
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.5
- Disclosed:
- May 2, 2024
CVE-2024-2765 on NVD →
Ultimate Member <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output esca...
- CVSS:
- 5.4
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.5
- Disclosed:
- Apr 10, 2024
CVE-2024-2765 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.8.3
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio...
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- Mar 13, 2024
CVE-2024-1071 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.8.4
unknown
[en] The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. Thi...
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- Mar 13, 2024
CVE-2024-2123 on NVD →
Ultimate Member <= 2.8.3 - Unauthenticated Stored Cross-Site Scripting
high
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This mak...
- CVSS:
- 7.2
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.4
- Disclosed:
- Mar 8, 2024
CVE-2024-2123 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.1.3 - 2.8.2 - Unauthenticated SQL Injection
critical
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
- CVSS:
- 9.8
- Affected:
- 2.1.3 – 2.8.2
- Fixed in:
- 2.8.3
- Disclosed:
- Feb 23, 2024
CVE-2024-1071 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.6.9
unknown
Update the WordPress Ultimate Member plugin to the latest available version (at least 2.6.9).
WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Ultimate Member Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under...
- Affected:
- up to 2.6.9
- Fixed in:
- 2.6.9
- Disclosed:
- Aug 9, 2023
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.6.8 - Cross-Site Request Forgery
medium
The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.8. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to invoke select functions using the 'um_admin_do_action__'...
- CVSS:
- 4.3
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.9
- Disclosed:
- Aug 8, 2023
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.6.9
unknown
The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.8. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to invoke select functions using the 'um_admin_do_action__'...
- Affected:
- up to 2.6.9
- Fixed in:
- 2.6.9
- Disclosed:
- Aug 8, 2023
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.6.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Jul 17, 2023
CVE-2023-31216 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.6.7
unknown
[en] The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Jul 4, 2023
CVE-2023-3460 on NVD →
Ultimate Member <= 2.6.6 - Privilege Escalation via Arbitrary User Meta Updates
critical
The Ultimate Member plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.6. This is due to the plugin using a predefined list of user meta keys that are banned which can be bypassed via a few method like adding slashes to the user meta key. This makes it possible for unauthen...
- CVSS:
- 9.8
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- Jun 29, 2023
CVE-2023-3460 on NVD →
Ultimate Member <= 2.6.0 - Cross-Site Request Forgery to Form Duplication
medium
The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.0. This is due to missing or incorrect nonce validation on the duplicate_form function. This makes it possible for unauthenticated attackers to duplicate forms created with the plugin via a forged...
- CVSS:
- 4.3
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- May 30, 2023
CVE-2023-31216 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.5.1
unknown
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Apr 13, 2023
CVE-2022-2445 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.5.1
unknown
[en] The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). This makes it possible for authenticated attackers, with administrative ca...
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Nov 29, 2022
CVE-2022-3383 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.5.1
unknown
[en] The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP functions like phpinfo(); since user su...
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Nov 29, 2022
CVE-2022-3384 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.5.1
unknown
[en] The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply arbitrary paths using traversal (.....
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Nov 29, 2022
CVE-2022-3361 on NVD →
Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Limited Remote Code Execution via um_populate_dropdown_options
high
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP functions like phpinfo(); since user supplie...
- CVSS:
- 7.2
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Oct 28, 2022
CVE-2022-3384 on NVD →
Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Remote Code Execution via Multi-Select
high
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). This makes it possible for authenticated attackers, with administrative capabil...
- CVSS:
- 7.2
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Oct 28, 2022
CVE-2022-3383 on NVD →
Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Directory Traversal
medium
The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'pack' parameter. This makes it possible for attackers with administrative privileges to supply arbitrary paths using traversal (../../) to access and include...
- CVSS:
- 4.7
- Affected:
- 1.0 – 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Oct 28, 2022
CVE-2022-2445 on NVD →
Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Contributor+) Directory Traversal via Shortcodes
medium
The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply arbitrary paths using traversal (../../)...
- CVSS:
- 4.3
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Oct 28, 2022
CVE-2022-3361 on NVD →
Ultimate Member <= 2.4.0 - Subscriber+ Stored Cross-Site Scripting
medium
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘website’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject...
- CVSS:
- 5.4
- Affected:
- 2.4.0 – 2.4.0
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 15, 2022
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.4.1
unknown
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘website’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject...
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 15, 2022
Ultimate Member <= 2.4.1 - Username Enumeration
high
The Ultimate Member plugin for WordPress is vulnerable to Username Enumeration in versions up to, and including, 2.4.1 via the um_get_members ajax action. This allows unauthenticated attackers to obtain a list of users including user names on that site.
- CVSS:
- 7.5
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Jul 14, 2022
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.4.2
unknown
The Ultimate Member plugin for WordPress is vulnerable to Username Enumeration in versions up to, and including, 2.4.1 via the um_get_members ajax action. This allows unauthenticated attackers to obtain a list of users including user names on that site.
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Jul 14, 2022
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.4.0
unknown
[en] The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding that is reflected back on the page....
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.0
- Disclosed:
- Jun 13, 2022
CVE-2022-1208 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.3.2
unknown
[en] The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- May 10, 2022
CVE-2022-1209 on NVD →
Ultimate Member <= 2.3.1 - Arbitrary Redirect
medium
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
- CVSS:
- 4.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Apr 29, 2022
CVE-2022-1209 on NVD →
Ultimate Member <= 2.3.2 - Stored Cross-Site Scripting
medium
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input sanitization and output escaping that allows users to encode malicious web scripts with HTML encoding that is reflected back on the page. This...
- CVSS:
- 6.4
- Affected:
- up to 2.3.2
- Fixed in:
- 2.4.0
- Disclosed:
- Mar 21, 2022
CVE-2022-1208 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.20
unknown
[en] The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site Scripting issue. Knowledge of the target...
- Affected:
- up to 2.1.20
- Fixed in:
- 2.1.20
- Disclosed:
- May 24, 2021
CVE-2021-24306 on NVD →
Ultimate Member <= 2.1.19 - Reflected Cross-Site Scripting
medium
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site Scripting issue. Knowledge of the targeted us...
- CVSS:
- 6.1
- Affected:
- up to 2.1.20
- Fixed in:
- 2.1.20
- Disclosed:
- May 7, 2021
CVE-2021-24306 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.13
unknown
[en] The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
- Affected:
- up to 2.1.13
- Fixed in:
- 2.1.13
- Disclosed:
- Jan 6, 2021
CVE-2020-36170 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.12
unknown
[en] An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted...
- Affected:
- up to 2.1.12
- Fixed in:
- 2.1.12
- Disclosed:
- Jan 4, 2021
CVE-2020-36155 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.12
unknown
[en] An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to any role (e.g., Administrator) during a profile update, and effe...
- Affected:
- up to 2.1.12
- Fixed in:
- 2.1.12
- Disclosed:
- Jan 4, 2021
CVE-2020-36156 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.12
unknown
[en] An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role parameter that could be supplied during the registration process, an attacker could supply the role parameter with a WordPress capabil...
- Affected:
- up to 2.1.12
- Fixed in:
- 2.1.12
- Disclosed:
- Jan 4, 2021
CVE-2020-36157 on NVD →
Ultimate Member <= 2.1.12 - Cross-Site Scripting
medium
The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
- CVSS:
- 6.5
- Affected:
- up to 2.1.13
- Fixed in:
- 2.1.13
- Disclosed:
- Dec 9, 2020
CVE-2020-36170 on NVD →
Ultimate Member <= 2.1.11 - Unauthenticated Privilege Escalation via User Roles
critical
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role parameter that could be supplied during the registration process, an attacker could supply the role parameter with a WordPress capability (...
- CVSS:
- 10
- Affected:
- up to 2.1.12
- Fixed in:
- 2.1.12
- Disclosed:
- Nov 9, 2020
CVE-2020-36157 on NVD →
Ultimate Member <= 2.1.11 - Unauthenticated Privilege Escalation via User Meta
critical
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted regi...
- CVSS:
- 10
- Affected:
- up to 2.1.12
- Fixed in:
- 2.1.12
- Disclosed:
- Nov 9, 2020
CVE-2020-36155 on NVD →
Ultimate Member <= 2.1.11 - Authenticated Privilege Escalation via Profile Update
critical
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to any role (e.g., Administrator) during a profile update, and effective...
- CVSS:
- 9.9
- Affected:
- up to 2.1.12
- Fixed in:
- 2.1.12
- Disclosed:
- Nov 9, 2020
CVE-2020-36156 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.12
unknown
Unauthenticated Privilege Escalation via User Meta vulnerability found by Chloe Chamberland in WordPress Ultimate Member plugin (versions <= 2.1.11).
- Affected:
- up to 2.1.12
- Fixed in:
- 2.1.12
- Disclosed:
- Nov 9, 2020
Ultimate Member <= 2.1.6 - Open Redirect
medium
The Ultimate Member plugin for WordPress is vulnerable to open redirects in versions up to, and including, 2.1.6 This is due to insufficient redirect location validation which makes it possible for unauthenticated attackers to trick victims into accessing malicious sites granted they can trick the victim into performin...
- CVSS:
- 6.1
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Jul 23, 2020
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.7
unknown
The Ultimate Member plugin for WordPress is vulnerable to open redirects in versions up to, and including, 2.1.6 This is due to insufficient redirect location validation which makes it possible for unauthenticated attackers to trick victims into accessing malicious sites granted they can trick the victim into performin...
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Jul 23, 2020
Ultimate Member <= 2.1.2 - Insecure Direct Object Reference
medium
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image.
- CVSS:
- 5.3
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Jan 13, 2020
CVE-2020-6859 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.3
unknown
[en] Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image.
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Jan 13, 2020
CVE-2020-6859 on NVD →
Ultimate Member <= 1.3.88 - Cross Site Scripting
medium
Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.1
- Affected:
- up to 1.3.88
- Fixed in:
- 2.0.4
- Disclosed:
- Aug 12, 2019
CVE-2018-0585 on NVD →
Ultimate Member <= 2.0.3 - Cross Site Scripting
medium
The ultimate-member plugin before 2.0.4 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Aug 12, 2019
CVE-2018-20965 on NVD →
Ultimate Member <= 2.0.3 - Unauthorized Image File Upload
medium
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
- CVSS:
- 4.3
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Aug 12, 2019
CVE-2018-0587 on NVD →
Ultimate Member <= 2.0.3 - Directory Traversal
medium
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.
- CVSS:
- 4.3
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Aug 12, 2019
CVE-2018-0586 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.40
unknown
[en] The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
- Affected:
- up to 1.3.40
- Fixed in:
- 1.3.40
- Disclosed:
- Aug 12, 2019
CVE-2016-10872 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.18
unknown
[en] The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
- Affected:
- up to 1.3.18
- Fixed in:
- 1.3.18
- Disclosed:
- Aug 12, 2019
CVE-2015-9304 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.54
unknown
[en] The ultimate-member plugin before 2.0.54 for WordPress has XSS.
- Affected:
- up to 2.0.54
- Fixed in:
- 2.0.54
- Disclosed:
- Aug 12, 2019
CVE-2019-14945 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.52
unknown
[en] The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
- Affected:
- up to 2.0.52
- Fixed in:
- 2.0.52
- Disclosed:
- Aug 12, 2019
CVE-2019-14946 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.52
unknown
[en] The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
- Affected:
- up to 2.0.52
- Fixed in:
- 2.0.52
- Disclosed:
- Aug 12, 2019
CVE-2019-14947 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4
unknown
[en] The ultimate-member plugin before 2.0.4 for WordPress has XSS.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Aug 12, 2019
CVE-2018-20965 on NVD →
Ultimate Member <= 2.0.53 - Cross-Site Scripting
medium
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
- CVSS:
- 6.4
- Affected:
- up to 2.0.53
- Fixed in:
- 2.0.54
- Disclosed:
- Jul 22, 2019
CVE-2019-14945 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.52
unknown
Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities found by m0ns7er in WordPress Ultimate Member plugin (versions <= 2.0.51).
- Affected:
- up to 2.0.52
- Fixed in:
- 2.0.52
- Disclosed:
- Jul 13, 2019
Ultimate Member <= 2.0.51 - Cross-Site Request Forgery and Stored Cross-Site Scripting
medium
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
- CVSS:
- 6.1
- Affected:
- up to 2.0.51
- Fixed in:
- 2.0.52
- Disclosed:
- Jun 24, 2019
CVE-2019-14946 on NVD →
Ultimate Member <= 2.0.51 - Cross-Site Request Forgery and Stored Cross-Site Scripting
medium
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
- CVSS:
- 5.4
- Affected:
- up to 2.0.51
- Fixed in:
- 2.0.52
- Disclosed:
- Jun 24, 2019
CVE-2019-14947 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.40
unknown
[en] An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures of privileged users. To perform such...
- Affected:
- up to 2.0.40
- Fixed in:
- 2.0.40
- Disclosed:
- Jun 24, 2019
CVE-2019-10271 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.40
unknown
[en] An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id parameter) to reset the password of another user. One only needs to know the user_id, which is p...
- Affected:
- up to 2.0.40
- Fixed in:
- 2.0.40
- Disclosed:
- Jun 21, 2019
CVE-2019-10270 on NVD →
Ultimate Member <= 2.0.39 - Privilege Escalation
high
An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.0.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id parameter) to reset the password of another user. One only needs to know the user_id, which is publ...
- CVSS:
- 8.8
- Affected:
- up to 2.0.39
- Fixed in:
- 2.0.40
- Disclosed:
- Jun 15, 2019
CVE-2019-10270 on NVD →
Ultimate Member <= 2.0.39 - Unauthorized Profile Modification
medium
An issue was discovered in the Ultimate Member plugin 2.0.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and cover picture of any user once one is connected. One can also modify the profiles and cover pictures of privileged users. To perform such a...
- CVSS:
- 4.3
- Affected:
- up to 2.0.39
- Fixed in:
- 2.0.40
- Disclosed:
- Jun 15, 2019
CVE-2019-10271 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.46
unknown
Multiple vulnerabilities found by Antony Garand (Sucuri team) in WordPress Ultimate Member plugin (versions <= 2.0.45).
- Affected:
- up to 2.0.46
- Fixed in:
- 2.0.46
- Disclosed:
- May 16, 2019
Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.0.45 - Arbitrary File Deletion/Read
critical
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin plugin for WordPress is vulnerable to arbitrary file deletion and reading when the file upload functionality is enabled for the user profile and registration forms in versions up to, and including 2.0.45. This is due to the fact that the p...
- CVSS:
- 9.4
- Affected:
- up to 2.0.45
- Fixed in:
- 2.0.46
- Disclosed:
- May 13, 2019
Ultimate Member <= 2.0.45 - Low-Privileged Stored Cross-Site Scripting
medium
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file's name from a user profile upload in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for low-level authenticated attackers to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 2.0.45
- Fixed in:
- 2.0.46
- Disclosed:
- May 13, 2019
Ultimate Member <= 2.0.45 - Admin+ Stored Cross-Site Scripting
medium
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several of the plugin's form parameter in versions up to, and including,2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level capabiliti...
- CVSS:
- 5.5
- Affected:
- up to 2.0.46
- Fixed in:
- 2.0.46
- Disclosed:
- May 13, 2019
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.46
unknown
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several of the plugin's form parameter in versions up to, and including,2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level capabiliti...
- Affected:
- up to 2.0.46
- Fixed in:
- 2.0.46
- Disclosed:
- May 13, 2019
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.46
unknown
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin plugin for WordPress is vulnerable to arbitrary file deletion and reading when the file upload functionality is enabled for the user profile and registration forms in versions up to, and including 2.0.45. This is due to the fact that the p...
- Affected:
- up to 2.0.46
- Fixed in:
- 2.0.46
- Disclosed:
- May 13, 2019
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.46
unknown
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file's name from a user profile upload in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for low-level authenticated attackers to inject arbitra...
- Affected:
- up to 2.0.46
- Fixed in:
- 2.0.46
- Disclosed:
- May 13, 2019
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.40
unknown
[en] A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator prof...
- Affected:
- up to 2.0.40
- Fixed in:
- 2.0.40
- Disclosed:
- Apr 3, 2019
CVE-2019-10673 on NVD →
Ultimate Member <= 2.0.39 - Cross-Site Request Forgery
high
A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator profile,...
- CVSS:
- 8.8
- Affected:
- up to 2.0.40
- Fixed in:
- 2.0.40
- Disclosed:
- Apr 1, 2019
CVE-2019-10673 on NVD →
Ultimate Member <= 2.0.32 - Cross-Site Request Forgery
medium
The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.32. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to execute arbitrary actions via forged requests granted they can...
- CVSS:
- 6.1
- Affected:
- up to 2.0.32
- Fixed in:
- 2.0.33
- Disclosed:
- Nov 27, 2018
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.33
unknown
Cross-Site Request Forgery (CSRF) vulnerability found in WordPress Ultimate Member plugin (versions <= 2.0.32).
- Affected:
- up to 2.0.33
- Fixed in:
- 2.0.33
- Disclosed:
- Nov 27, 2018
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.33
unknown
The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.32. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to execute arbitrary actions via forged requests granted they can...
- Affected:
- up to 2.0.33
- Fixed in:
- 2.0.33
- Disclosed:
- Nov 27, 2018
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.28
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.
- Affected:
- up to 2.0.28
- Fixed in:
- 2.0.28
- Disclosed:
- Oct 9, 2018
CVE-2018-17866 on NVD →
Ultimate Member <= 2.0.27 - Multiple Cross-Site Scripting vulnerabilities
medium
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.
- CVSS:
- 6.1
- Affected:
- up to 2.0.27
- Fixed in:
- 2.0.28
- Disclosed:
- Oct 6, 2018
CVE-2018-17866 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.22
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found in WordPress Ultimate Member plugin (versions <= 2.0.21).
- Affected:
- up to 2.0.22
- Fixed in:
- 2.0.22
- Disclosed:
- Aug 28, 2018
Ultimate Member <= 2.0.21 - Cross-Site Scripting
medium
The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.21 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 2.0.22
- Fixed in:
- 2.0.22
- Disclosed:
- Aug 9, 2018
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.22
unknown
Unauthenticated Arbitrary File Upload vulnerability found in WordPress Ultimate Member plugin (versions <= 2.0.21).
- Affected:
- up to 2.0.22
- Fixed in:
- 2.0.22
- Disclosed:
- Aug 9, 2018
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.22
unknown
The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.21 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.0.22
- Fixed in:
- 2.0.22
- Disclosed:
- Aug 9, 2018
Ultimate Member <= 2.0.21 - Arbitrary File Upload
high
The Arbitrary File Upload plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.0.21. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- CVSS:
- 8.8
- Affected:
- up to 2.0.22
- Fixed in:
- 2.0.22
- Disclosed:
- Aug 8, 2018
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.22
unknown
The Arbitrary File Upload plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.0.21. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- Affected:
- up to 2.0.22
- Fixed in:
- 2.0.22
- Disclosed:
- Aug 8, 2018
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.18
unknown
[en] The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
- Affected:
- up to 2.0.18
- Fixed in:
- 2.0.18
- Disclosed:
- Jul 4, 2018
CVE-2018-13136 on NVD →
Ultimate Member <= 2.0.17 - Authenticated Cross-Site Scripting
medium
The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen.
- CVSS:
- 6.1
- Affected:
- up to 2.0.17
- Fixed in:
- 2.0.18
- Disclosed:
- Jul 3, 2018
CVE-2018-13136 on NVD →
Ultimate Member <= 2.0.3 - Improper Access Control
medium
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.
- CVSS:
- 4.3
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- May 14, 2018
CVE-2018-0589 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4
unknown
[en] Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- May 14, 2018
CVE-2018-0589 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4
unknown
[en] Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- May 14, 2018
CVE-2018-0590 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4
unknown
[en] Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- May 14, 2018
CVE-2018-0585 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.40
unknown
[en] Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
- Affected:
- up to 2.0.40
- Fixed in:
- 2.0.40
- Disclosed:
- May 14, 2018
CVE-2018-0588 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4
unknown
[en] Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- May 14, 2018
CVE-2018-0586 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4
unknown
[en] Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- May 14, 2018
CVE-2018-0587 on NVD →
Ultimate Member < 2.0.4 - Insecure Direct Object Reference
medium
The Ultimate Member plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions prior to version 2.0.4. This is due to bypass access restriction via unspecified vectors. This makes it possible for authenticated attackers to modify the other users profiles via unspecified vectors.
- CVSS:
- 4.3
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- May 10, 2018
CVE-2018-0590 on NVD →
Ultimate Member <= 2.0.39 - Directory Traversal
medium
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
- CVSS:
- 4.3
- Affected:
- up to 2.0.39
- Fixed in:
- 2.0.40
- Disclosed:
- May 10, 2018
CVE-2018-0588 on NVD →
Ultimate Member < 2.0.4 - Authenticated Unrestricted File Upload
medium
The Ultimate Member plugin for WordPress is vulnerable to unrestricted file uploads in versions prior to version 2.0.4. This makes it possible for authenticated attackers to upload arbitrary image files via unspecified vectors.
- CVSS:
- 4.3
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- May 10, 2018
CVE-2018-0587 on NVD →
Ultimate Member <= 2.0.6 - Multiple Cross-Site Request Forgery Issues
high
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
- CVSS:
- 8.8
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Apr 23, 2018
CVE-2018-10233 on NVD →
Ultimate Member <= 2.0.10 - Authenticated Cross-Site Scripting
medium
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.
- CVSS:
- 5.5
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.11
- Disclosed:
- Apr 23, 2018
CVE-2018-10234 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.7
unknown
[en] The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Apr 23, 2018
CVE-2018-10233 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.11
unknown
[en] Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.11
- Disclosed:
- Apr 23, 2018
CVE-2018-10234 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4
unknown
[en] core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Feb 16, 2018
CVE-2018-6943 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.4
unknown
[en] core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Feb 16, 2018
CVE-2018-6944 on NVD →
Ultimate Member <= 2.0.3 - Cross-Site Scripting
medium
core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
- CVSS:
- 6.1
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Feb 14, 2018
CVE-2018-6943 on NVD →
Ultimate Member <= 2.0 - Cross-Site Scripting
medium
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
- CVSS:
- 6.1
- Affected:
- up to 2.0
- Fixed in:
- 2.0.4
- Disclosed:
- Feb 14, 2018
CVE-2018-6944 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.29
unknown
[en] Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.
- Affected:
- up to 1.3.29
- Fixed in:
- 1.3.29
- Disclosed:
- Sep 11, 2017
CVE-2015-8354 on NVD →
Ultimate Member <= 1.3.83 - Shortcode Injection
critical
The Ultimate Member plugin for WordPress is vulnerable to Executing Arbitrary WordPress Shortcodes in versions up to, and including, 1.3.83. This is due to 'ultimatemember_frontend_modal' AJAX action allowing for the execution of the 'do_shortcode()' function. This makes it possible for unauthenticated attackers to exe...
- CVSS:
- 9.8
- Affected:
- up to 1.3.83
- Fixed in:
- 1.3.84
- Disclosed:
- Apr 17, 2017
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.84
unknown
The Ultimate Member plugin for WordPress is vulnerable to Executing Arbitrary WordPress Shortcodes in versions up to, and including, 1.3.83. This is due to 'ultimatemember_frontend_modal' AJAX action allowing for the execution of the 'do_shortcode()' function. This makes it possible for unauthenticated attackers to exe...
- Affected:
- up to 1.3.84
- Fixed in:
- 1.3.84
- Disclosed:
- Apr 17, 2017
Ultimate Member <= 1.3.75 - Missing Authorization to Password Reset
critical
The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 1.3.75. This makes it possible for unauthenticated attackers to change the passwords of any user within the vulnerabilities scope.
- CVSS:
- 9.8
- Affected:
- up to 1.3.75
- Fixed in:
- 1.3.76
- Disclosed:
- Dec 6, 2016
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.76
unknown
This plugin is prone to an unauthenticated change passwords vulnerability.
Update the plugin.
- Affected:
- up to 1.3.76
- Fixed in:
- 1.3.76
- Disclosed:
- Dec 6, 2016
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.76
unknown
The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 1.3.75. This makes it possible for unauthenticated attackers to change the passwords of any user within the vulnerabilities scope.
- Affected:
- up to 1.3.76
- Fixed in:
- 1.3.76
- Disclosed:
- Dec 6, 2016
Ultimate Member <= 1.3.64 - Local File Inclusion
critical
The Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.64 via the 'page' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass...
- CVSS:
- 9.1
- Affected:
- up to 1.3.65
- Fixed in:
- 1.3.65
- Disclosed:
- Jul 10, 2016
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.65
unknown
This plugin is prone to a PHP file inclusion vulnerability.
Update the plugin.
- Affected:
- up to 1.3.65
- Fixed in:
- 1.3.65
- Disclosed:
- Jul 10, 2016
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.65
unknown
The Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.64 via the 'page' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass...
- Affected:
- up to 1.3.65
- Fixed in:
- 1.3.65
- Disclosed:
- Jul 10, 2016
Ultimate Member <= 1.3.39 - Cross-Site Scripting
medium
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
- CVSS:
- 6.1
- Affected:
- up to 1.3.40
- Fixed in:
- 1.3.40
- Disclosed:
- Apr 6, 2016
CVE-2016-10872 on NVD →
Ultimate Member <= 1.3.28 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.
- CVSS:
- 6.1
- Affected:
- up to 1.3.29
- Fixed in:
- 1.3.29
- Disclosed:
- Dec 2, 2015
CVE-2015-8354 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.29
unknown
Because of this vulnerability, attackers cat steal administrator's cookies, credentials and browser history and modify web page content to perform phishing attacks.
Update the plugin.
- Affected:
- up to 1.3.29
- Fixed in:
- 1.3.29
- Disclosed:
- Dec 2, 2015
Ultimate Member <= 1.3.17 - Cross-Site Scripting
medium
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
- CVSS:
- 6.1
- Affected:
- up to 1.3.17
- Fixed in:
- 1.3.18
- Disclosed:
- Aug 20, 2015
CVE-2015-9304 on NVD →
Ultimate Member 1.2.98 - 1.2.997 - Reflected Cross-Site Scripting
high
The Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in versions 1.2.98 through 1.2.997 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...
- CVSS:
- 7.1
- Affected:
- 1.2.98 – 1.2.997
- Fixed in:
- 1.3.0
- Disclosed:
- Jun 18, 2015
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.2.995
unknown
This plugin is prone to a cross site scripting vulnerability, because attackers load data from a location. After that, data from that location is output on the target domain and JavaScript is executed under the context of the current user of the site.
Update the plugin.
- Affected:
- up to 1.2.995
- Fixed in:
- 1.2.995
- Disclosed:
- Jun 18, 2015
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.2.995
unknown
The Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in versions 1.2.98 through 1.2.997 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...
- Affected:
- up to 1.2.995
- Fixed in:
- 1.2.995
- Disclosed:
- Jun 18, 2015
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.0.84
unknown
Because of multiple vulnerabilities in this plugin, attackers can delete any file or upload arbitrary files.
Update the plugin.
- Affected:
- up to 1.0.84
- Fixed in:
- 1.0.84
- Disclosed:
- Mar 16, 2015
Ultimate Member < 1.0.84 - Authorization Bypass to Arbitrary File Upload/Delete
critical
The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ultimatemember_remove_file() function in versions up to, and including, 1.0.83. This makes it possible for unauthenticated attackers to delete or upload arbitrary files.
- CVSS:
- 9.8
- Affected:
- up to 1.0.84
- Fixed in:
- 1.0.84
- Disclosed:
- Mar 10, 2015
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.0.84
unknown
The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ultimatemember_remove_file() function in versions up to, and including, 1.0.83. This makes it possible for unauthenticated attackers to delete or upload arbitrary files.
- Affected:
- up to 1.0.84
- Fixed in:
- 1.0.84
- Disclosed:
- Mar 10, 2015
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.1.7
unknown
The Ultimate Member WordPress plugin was vulnerable to an Unauthenticated Open Redirect vulnerability, affecting the registration and login pages where the "redirect_to" GET parameter was used.
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.46
unknown
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.
- Affected:
- up to 2.0.46
- Fixed in:
- 2.0.46
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.33
unknown
- Affected:
- up to 2.0.33
- Fixed in:
- 2.0.33
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.22
unknown
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.0.22
- Fixed in:
- 2.0.22
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.22
unknown
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin was affected by an Unauthenticated Arbitrary File Upload security vulnerability.
- Affected:
- up to 2.0.22
- Fixed in:
- 2.0.22
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.76
unknown
Ultimate Member versions below 1.3.76 contain a critical security issue that allows unauthenticated users to reset any users password to an arbitrary value
- Affected:
- up to 1.3.76
- Fixed in:
- 1.3.76
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.3.65
unknown
It was discovered that Ultimate Member is vulnerable to PHP File Inclusion. In order to exploit this issue an attacker must be able to place an arbitrary PHP file on the target system. Afterwards the attacker needs to lure an authenticated admin to visit a malicious page. Through CSRF the attacker could compromise Word...
- Affected:
- up to 1.3.65
- Fixed in:
- 1.3.65
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] >= 1.2.98 - <= 1.2.994
unknown
The Ultimate Member plugin utilizes the Redux Framework. The Redux Framework includes a script named ‘class.p.php’, which acts as a HTTP proxy.
Utilizing this script, it is possible to trigger a Reflected XSS attack, by loading data from a location controlled by the attacker. The data from this location...
- Affected:
- 1.2.98 – 1.2.994
- Fixed in:
- 1.2.994
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 1.0.84
unknown
Ultimate Member Plugin version 1.0.78 has several security vulnerabilities that allow unauthenticated users to delete and upload files, which can ultimately lead to remote code execution.
- Affected:
- up to 1.0.84
- Fixed in:
- 1.0.84
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.9.2
unknown
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
CVE-2025-0318 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.9.2
unknown
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
CVE-2025-0308 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.10.1
unknown
- Affected:
- up to 2.10.1
- Fixed in:
- 2.10.1
CVE-2025-1702 on NVD →
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.10.2
unknown
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on the user supplied parameter and lac...
- Affected:
- up to 2.10.2
- Fixed in:
- 2.10.2