plugin

Users Ultra Vulnerabilities

33 known security issues reported for the Users Ultra WordPress plugin. Most recent disclosed Apr 25, 2022.

4 critical 6 high 2 medium

Running Users Ultra on your site? Check whether your installed version is affected.

Scan your site free

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] <= 3.1.0 (unfixed + closed)

unknown

[en] The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

Affected:
up to 3.1.0
Fix:
No patched version reported
Disclosed:
Apr 25, 2022

CVE-2022-0769 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 3.1.0 - Unauthenticated SQL Injection

critical

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

CVSS:
9.8
Affected:
up to 3.1.0
Fix:
No patched version reported
Disclosed:
Apr 13, 2022

CVE-2022-0769 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.63 (closed)

unknown

[en] The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter.

Affected:
up to 1.5.63
Fixed in:
1.5.63
Disclosed:
Sep 20, 2019

CVE-2015-9393 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.59 (closed)

unknown

[en] The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.

Affected:
up to 1.5.59
Fixed in:
1.5.59
Disclosed:
Sep 20, 2019

CVE-2015-9402 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.63 (closed)

unknown

[en] The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.

Affected:
up to 1.5.63
Fixed in:
1.5.63
Disclosed:
Sep 20, 2019

CVE-2015-9394 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.64 (closed)

unknown

[en] The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.

Affected:
up to 1.5.64
Fixed in:
1.5.64
Disclosed:
Sep 20, 2019

CVE-2015-9395 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.51 (closed)

unknown

Because of this vulnerability, an attacker can change tag, type, description, photo or video name, category or unique id by setting POST parameters, such as "photo_desc", "photo_tags" or "photo name", "video_type", "video_name", etc. Update the plugin.

Affected:
up to 1.5.51
Fixed in:
1.5.51
Disclosed:
Dec 3, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.51 (closed)

unknown

Because of this vulnerability, an attacker can include JavaScript code in package name or description. Upgrade the plugin.

Affected:
up to 1.5.51
Fixed in:
1.5.51
Disclosed:
Dec 3, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.5.63 - Cross-Site Request Forgery

high

The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.

CVSS:
8.8
Affected:
up to 1.5.63
Fixed in:
1.5.63
Disclosed:
Dec 2, 2015

CVE-2015-9394 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.5.63 - Cross-Site Scripting

medium

The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter.

CVSS:
6.1
Affected:
up to 1.5.63
Fixed in:
1.5.63
Disclosed:
Dec 2, 2015

CVE-2015-9393 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.5.63 - Cross-Site Scripting via p_name parameter

medium

The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter.

CVSS:
5.4
Affected:
up to 1.5.63
Fixed in:
1.5.63
Disclosed:
Dec 2, 2015

CVE-2015-9392 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.63 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.5.63
Fixed in:
1.5.63
Disclosed:
Dec 2, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.64 (closed)

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 1.5.64
Fixed in:
1.5.64
Disclosed:
Dec 2, 2015

Users Ultra Membership Plugin <= 1.5.63 - Authenticated Blind SQL Injection

high

The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via ajax actions, by exploiting following WP ajax actions SQL injections attacks can be performed: `edit_video`, `delete_photo`, `delete_gallery`, `delete_video`, `reload_photos`, `edit_gallery`, `edit_gallery_confirm`, `edit_photo`, `edit_photo_con...

CVSS:
8.8
Affected:
up to 1.5.64
Fixed in:
1.5.64
Disclosed:
Dec 1, 2015

CVE-2015-9395 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.51 (closed)

unknown

Because of this vulnerability, there is no sanitization for values in CSV file (this file is accessible by anyone), all additional columns are in this file. In this way, an attacker can create and activate user accounts and compromise the whole site. Upgrade the plugin.

Affected:
up to 1.5.51
Fixed in:
1.5.51
Disclosed:
Nov 18, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.5.58 - Arbitrary File Upload

high

The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.

CVSS:
8.8
Affected:
up to 1.5.59
Fixed in:
1.5.59
Disclosed:
Nov 17, 2015

CVE-2015-9402 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.59 (closed)

unknown

Because of this vulnerability, any user can exploit a misbehavior of the plugin in order to upload csv files to the infected website. Update the plugin.

Affected:
up to 1.5.59
Fixed in:
1.5.59
Disclosed:
Nov 17, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.5.16 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) data_target or (2) data_vote parameter in a rating_vote (wp_ajax_nopriv_rating_vote) action to wp-admin/admin-ajax.php.

Affected:
up to 1.5.16
Fixed in:
1.5.16
Disclosed:
Jun 9, 2015

CVE-2015-4109 on NVD →

Users Ultra <= 1.5.15 - Multiple SQL Injection

critical

Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) data_target or (2) data_vote parameter in a rating_vote (wp_ajax_nopriv_rating_vote) action to wp-admin/admin-ajax.php.

CVSS:
9.8
Affected:
up to 1.5.15
Fixed in:
1.5.16
Disclosed:
Jun 4, 2015

CVE-2015-4109 on NVD →

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.4.95 - SQL Injection

high

The "Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin" plugin for WordPress is vulnerable to SQL Injection via the ‘$gal_id’ parameter in versions up to, and including, 1.4.95 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

CVSS:
7.2
Affected:
up to 1.4.95
Fixed in:
1.4.96
Disclosed:
Apr 17, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.4.96

unknown

The "Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin" plugin for WordPress is vulnerable to SQL Injection via the ‘$gal_id’ parameter in versions up to, and including, 1.4.95 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

Affected:
up to 1.4.96
Fixed in:
1.4.96
Disclosed:
Apr 17, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.4.36 - SQL Injection

high

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin for WordPress is vulnerable to generic SQL Injection via the ‘cate_id’ parameter in versions up to, and including, 1.4.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e...

CVSS:
8.8
Affected:
up to 1.4.36
Fixed in:
1.4.36
Disclosed:
Feb 9, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.4.36 (closed)

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Upgrade the plugin.

Affected:
up to 1.4.36
Fixed in:
1.4.36
Disclosed:
Feb 9, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.4.36

unknown

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin for WordPress is vulnerable to generic SQL Injection via the ‘cate_id’ parameter in versions up to, and including, 1.4.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e...

Affected:
up to 1.4.36
Fixed in:
1.4.36
Disclosed:
Feb 9, 2015

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.3.58 - SQL Injection

critical

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.58 due to insufficient escaping on the user-supplied $id parameter and lack of sufficient preparation on the existing SQL query. This m...

CVSS:
9.8
Affected:
up to 1.3.58
Fixed in:
1.3.59
Disclosed:
Oct 22, 2014

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.3.58 - SQL Injection

critical

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.58 due to insufficient escaping on the user-supplied $id parameter and lack of sufficient preparation on the existing SQL query. This m...

CVSS:
9.8
Affected:
up to 1.3.58
Fixed in:
1.3.59
Disclosed:
Oct 22, 2014

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.3.59

unknown

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.58 due to insufficient escaping on the user-supplied $id parameter and lack of sufficient preparation on the existing SQL query. This m...

Affected:
up to 1.3.59
Fixed in:
1.3.59
Disclosed:
Oct 22, 2014

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.3.59

unknown

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.58 due to insufficient escaping on the user-supplied $id parameter and lack of sufficient preparation on the existing SQL query. This m...

Affected:
up to 1.3.59
Fixed in:
1.3.59
Disclosed:
Oct 22, 2014

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.3.38 (closed)

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 1.3.38
Fixed in:
1.3.38
Disclosed:
Oct 7, 2014

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 3.1.0 - SQL Injection

high

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.0 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...

CVSS:
8.8
Affected:
up to 3.1.0
Fix:
No patched version reported
Disclosed:
Sep 29, 2014

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.3.38 (closed)

unknown

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.0 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...

Affected:
up to 1.3.38
Fixed in:
1.3.38
Disclosed:
Sep 29, 2014

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.4.36

unknown

The AJAX action &lsquo;edit_photo_cate&rsquo;, which is defined in the file &lsquo;users-ultra/addons/photocategories/admin/admin.php&rsquo;, allows for SQL Injection via the POST parameter &lsquo;cate_id&rsquo;. This parameter is used in a call to the WordPress function &lsquo;$wpdb-&gt;get_results()&rsquo; without be...

Affected:
up to 1.4.36
Fixed in:
1.4.36

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin [users-ultra] < 1.3.38

unknown
Affected:
up to 1.3.38
Fixed in:
1.3.38

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database