plugin

Ultimate Member Widgets For Elementor Vulnerabilities

2 known security issues reported for the Ultimate Member Widgets For Elementor WordPress plugin. Most recent disclosed Nov 27, 2025.

2 medium

Running Ultimate Member Widgets For Elementor on your site? Check whether your installed version is affected.

Scan your site free

Ultimate Member Widgets for Elementor <= 2.3 - Unauthenticated Information Exposure

medium

The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Nov 27, 2025

CVE-2025-66116 on NVD →

Ultimate Member Widgets for Elementor <= 2.3 - Missing Authorization to Unauthenticated Information Exposure

medium

The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_filter_users function in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to extract partial...

CVSS:
5.3
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Nov 19, 2025

CVE-2025-12778 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database