Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

Explore Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin vulnerabilities across all versions. Currently tracking 73 known vulnerabilities, including severity, impact, and patch status.

01234567891021.01.2015Today10.03.20159.8Ultimate Member < 1.0.84 - Authorization Bypass to Arbitrary File Upload/Delete CVSS 9.8 · 10.03.201518.06.20157.1Ultimate Member 1.2.98 - 1.2.997 - Reflected Cross-Site Scripting CVSS 7.1 · 18.06.201520.08.20156.1Ultimate Member <= 1.3.17 - Cross-Site Scripting CVSS 6.1 · 20.08.201502.12.20156.1Ultimate Member <= 1.3.28 - Reflected Cross-Site Scripting CVSS 6.1 · 02.12.201506.04.20166.1Ultimate Member <= 1.3.39 - Cross-Site Scripting CVSS 6.1 · 06.04.201610.07.20169.1Ultimate Member <= 1.3.64 - Local File Inclusion CVSS 9.1 · 10.07.201606.12.20169.8Ultimate Member <= 1.3.75 - Missing Authorization to Password Reset CVSS 9.8 · 06.12.201617.04.20179.8Ultimate Member <= 1.3.83 - Shortcode Injection CVSS 9.8 · 17.04.201714.02.20186.1Ultimate Member <= 2.0.3 - Cross-Site Scripting CVSS 6.1 · 14.02.20186.1Ultimate Member <= 2.0 - Cross-Site Scripting CVSS 6.1 · 14.02.201823.04.20188.8Ultimate Member <= 2.0.6 - Multiple Cross-Site Request Forgery Issues CVSS 8.8 · 23.04.20185.5Ultimate Member <= 2.0.10 - Authenticated Cross-Site Scripting CVSS 5.5 · 23.04.201810.05.20184.3Ultimate Member <= 2.0.39 - Directory Traversal CVSS 4.3 · 10.05.20184.3Ultimate Member < 2.0.4 - Insecure Direct Object Reference CVSS 4.3 · 10.05.20184.3Ultimate Member < 2.0.4 - Authenticated Unrestricted File Upload CVSS 4.3 · 10.05.201814.05.20184.3Ultimate Member <= 2.0.3 - Improper Access Control CVSS 4.3 · 14.05.201803.07.20186.1Ultimate Member <= 2.0.17 - Authenticated Cross-Site Scripting CVSS 6.1 · 03.07.201808.08.20188.8Ultimate Member <= 2.0.21 - Arbitrary File Upload CVSS 8.8 · 08.08.201809.08.20186.1Ultimate Member <= 2.0.21 - Cross-Site Scripting CVSS 6.1 · 09.08.201806.10.20186.1Ultimate Member <= 2.0.27 - Multiple Cross-Site Scripting vulnerabilities CVSS 6.1 · 06.10.201827.11.20186.1Ultimate Member <= 2.0.32 - Cross-Site Request Forgery CVSS 6.1 · 27.11.201801.04.20198.8Ultimate Member <= 2.0.39 - Cross-Site Request Forgery CVSS 8.8 · 01.04.201913.05.20199.4Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.0.45 - Arbitrary File Deletion/Read CVSS 9.4 · 13.05.20195.5Ultimate Member <= 2.0.45 - Admin+ Stored Cross-Site Scripting CVSS 5.5 · 13.05.20196.4Ultimate Member <= 2.0.45 - Low-Privileged Stored Cross-Site Scripting CVSS 6.4 · 13.05.201915.06.20194.3Ultimate Member <= 2.0.39 - Unauthorized Profile Modification CVSS 4.3 · 15.06.20198.8Ultimate Member <= 2.0.39 - Privilege Escalation CVSS 8.8 · 15.06.201924.06.20196.1Ultimate Member <= 2.0.51 - Cross-Site Request Forgery and Stored Cross-Site Scripting CVSS 6.1 · 24.06.20195.4Ultimate Member <= 2.0.51 - Cross-Site Request Forgery and Stored Cross-Site Scripting CVSS 5.4 · 24.06.201922.07.20196.4Ultimate Member <= 2.0.53 - Cross-Site Scripting CVSS 6.4 · 22.07.201912.08.20194.3Ultimate Member <= 2.0.3 - Directory Traversal CVSS 4.3 · 12.08.20196.1Ultimate Member <= 2.0.3 - Cross Site Scripting CVSS 6.1 · 12.08.20196.1Ultimate Member <= 1.3.88 - Cross Site Scripting CVSS 6.1 · 12.08.20194.3Ultimate Member <= 2.0.3 - Unauthorized Image File Upload CVSS 4.3 · 12.08.201913.01.20205.3Ultimate Member <= 2.1.2 - Insecure Direct Object Reference CVSS 5.3 · 13.01.202023.07.20206.1Ultimate Member <= 2.1.6 - Open Redirect CVSS 6.1 · 23.07.202009.11.20209.9Ultimate Member <= 2.1.11 - Authenticated Privilege Escalation via Profile Update CVSS 9.9 · 09.11.202010.0Ultimate Member <= 2.1.11 - Unauthenticated Privilege Escalation via User Meta CVSS 10.0 · 09.11.202010.0Ultimate Member <= 2.1.11 - Unauthenticated Privilege Escalation via User Roles CVSS 10.0 · 09.11.202009.12.20206.5Ultimate Member <= 2.1.12 - Cross-Site Scripting CVSS 6.5 · 09.12.202007.05.20216.1Ultimate Member <= 2.1.19 - Reflected Cross-Site Scripting CVSS 6.1 · 07.05.202121.03.20226.4Ultimate Member <= 2.3.2 - Stored Cross-Site Scripting CVSS 6.4 · 21.03.202229.04.20224.3Ultimate Member <= 2.3.1 - Arbitrary Redirect CVSS 4.3 · 29.04.202214.07.20227.5Ultimate Member <= 2.4.1 - Username Enumeration CVSS 7.5 · 14.07.202215.07.20225.4Ultimate Member <= 2.4.0 - Subscriber+ Stored Cross-Site Scripting CVSS 5.4 · 15.07.202228.10.20224.7Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Directory Traversal CVSS 4.7 · 28.10.20227.2Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Remote Code Execution via Multi-Select CVSS 7.2 · 28.10.20227.2Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Limited Remote Code Execution via um_populate_dropdown_options CVSS 7.2 · 28.10.20224.3Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Contributor+) Directory Traversal via Shortcodes CVSS 4.3 · 28.10.202230.05.20234.3Ultimate Member <= 2.6.0 - Cross-Site Request Forgery to Form Duplication CVSS 4.3 · 30.05.202329.06.20239.8Ultimate Member <= 2.6.6 - Privilege Escalation via Arbitrary User Meta Updates CVSS 9.8 · 29.06.202308.08.20234.3Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.6.8 - Cross-Site Request Forgery CVSS 4.3 · 08.08.202323.02.20249.8Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.1.3 - 2.8.2 - Unauthenticated SQL Injection CVSS 9.8 · 23.02.202408.03.20247.2Ultimate Member <= 2.8.3 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 08.03.202410.04.20245.4Ultimate Member <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 5.4 · 10.04.202403.10.20246.4Ultimate Member <= 2.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 03.10.20245.3Ultimate Member <= 2.8.6 - Cross-Site Request Forgery to Membership Status Change CVSS 5.3 · 03.10.202420.11.20244.3Ultimate Member <= 2.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture Update CVSS 4.3 · 20.11.202417.01.20255.3Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure CVSS 5.3 · 17.01.20257.5Ultimate Member <= 2.9.1 - Unauthenticated SQL Injection CVSS 7.5 · 17.01.202520.02.20255.3Ultimate Member <= 2.9.2 - Authenticated SQL Injection CVSS 5.3 · 20.02.202504.03.20257.5Ultimate Member <= 2.10.0 - Unauthenticated SQL Injection via search Parameter CVSS 7.5 · 04.03.202516.04.20257.5Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection CVSS 7.5 · 16.04.202507.05.20257.2Ultimate Member <= 2.10.3 - Authenticated (Administrator+) Arbitrary Function Call CVSS 7.2 · 07.05.202516.12.20254.3Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Profile Privacy Setting Bypass CVSS 4.3 · 16.12.20256.4Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value' CVSS 6.4 · 16.12.202519.12.20255.3Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 - Unauthenticated Sensitive Information Exposure CVSS 5.3 · 19.12.202520.12.20256.4Ultimate Member <= 2.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes CVSS 6.4 · 20.12.202517.02.20266.1Ultimate Member <= 2.11.1 - Reflected Cross-Site Scripting via Filter Parameters CVSS 6.1 · 17.02.202627.03.20268.0Ultimate Member <= 2.11.2 - Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag CVSS 8.0 · 27.03.202603.04.20266.4Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets CVSS 6.4 · 03.04.202623.06.20268.8Ultimate Member <= 2.11.4 - Authenticated (Contributor+) Account Takeover via Password Reset Link Disclosure CVSS 8.8 · 23.06.202602.07.20266.4Ultimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field CVSS 6.4 · 02.07.2026

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

73

Get automatic notifications for all Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin vulnerabilities before they are exploited.

Vulnerability Records

73 records
2026-07-02 15:57CVE-2026-8489
6.4
Medium
darooYes
2026-06-23 00:00CVE-2026-7761
8.8
High
tiborisaakYes
2026-04-03 19:29CVE-2025-15064
6.4
Medium
tiborisaakYes
2026-03-27 09:48CVE-2026-4248
8.0
High
HDHYes
2026-02-17 00:00CVE-2026-1404
6.1
Medium
Dmitrii IgnatyevYes
2025-12-20 14:20CVE-2025-13220
6.4
Medium
Muhammad Yudha - DJYes
2025-12-19 19:56CVE-2025-12492
5.3
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2025-12-16 00:00CVE-2025-14081
4.3
Medium
Boris BogosavacYes
2025-12-16 00:00CVE-2025-13217
6.4
Medium
tiborisaakYes
2025-05-07 00:00CVE-2025-47691
7.2
High
Trương Hữu Phúc (truonghuuphuc)Yes
Showing 1–10 of 73 reports
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin banner
Latestv2.12.1

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &amp; Membership Plugin

Ultimate Member

Author

Ultimate Member

4.4(1,444)
88/100
Last Updated
2026-07-06 (23d ago)
Active Installs
200,000+
Downloads
13,349,953
Requires WP
6.2+
Requires PHP
7.0+
Tested up to
WP 7.0.2
Created
2015-01-21 (12y ago)

User Profile & Membership Plugin for WordPress The ultimate user profile & membership plugin for WordPress. The plugin makes it a breeze for users to sign-up and become members of your website. The plugin allows you to add beautiful user profiles to your site and is designed for creating advanced online communities and membership sites. Lightweight and highly extendible, Ultimate Member will enable you to create almost any type of site where users can join and become members with absolute ease. Features of the plugin include: Front-end user profiles Front-end user registration Front-end user login Custom form fields Conditional logic for form fields Drag and drop form builder User account page Custom user roles Member directories User emails Content restriction Conditional nav menus Show author posts & comments on user profiles Developer friendly with dozens of actions and filters Read about all of the plugin’s features at Ultimate Member Paid Extensions Ultimate Member has a range of extensions that allow you to extend the power of the plugin. You can purchase all of these extensions at a significant discount with one of our paid plans or you can purchase extensions individually. Zapier – Allow to integrate the Zapier popular apps with Ultimate Member Stripe – Sell paid memberships to access your website via Stripe subscriptions User Notes – Allow users to create public and private notes from their profile Profile Tabs – Allow to add the custom tabs to profiles User Locations – Allow to display users on a map on the member directory page and allow users to add their location via their profile Unsplash – Allow users to select a profile cover photo from Unsplash from their profile User Bookmarks – Allow users to bookmark content from your website User Photos – Allow users to upload photos to their profile Groups – Allow users to create and join groups around shared topics, interests etc. Private Content – Display private content to logged in users that only they can access User Tags – Lets you add a user tag system to your website Social Activity – Let users create public wall posts & see the activity of other users WooCommerce – Allow you to integrate WooCommerce with Ultimate Member Private Messages – Add a private messaging system to your site & allow users to message each other Followers – Allow users to follow each other on your site and protect their profile information Real-time Notifications – Add a notifications system to your site so users can receive real-time notifications Social Login – Let users register & login to your site via Facebook, Twitter, G+, LinkedIn, Instagram and Vkontakte (VK.com) bbPress – With the bbPress extension you can beautifully integrate Ultimate Member with bbPress MailChimp – Allow users to subscribe to your MailChimp lists when they signup on your site and sync user meta to MailChimp User Reviews – Allow users to rate & review each other using a 5 star rate/review system Verified Users – Add a user verification system to your site so user accounts can be verified myCRED – With the myCRED extension you can integrate Ultimate Member with the popular myCRED points management plugin Notices – Alert users to important information using conditional notices Profile Completeness – Encourage or force users to complete their profiles with the profile completeness extension Friends – Allows users to become friends by sending & accepting/rejecting friend requests Free Extensions JobsBoardWP – This free extension integrates Ultimate Member with the job board plugin JobBoardWP. ForumWP – This free extension integrates Ultimate Member with the forum plugin ForumWP. Terms & Conditions – Add a terms and condition checkbox to your registration forms & require users to agree to your T&Cs before registering on your site. Google reCAPTCHA – Stop bots on your registration & login forms with Google reCAPTCHA Online Users – Display what users are online with this extension Theme Our official theme is purpose built for websites that have logged in and out users. The theme has deep integration with Ultimate Member plugin and the extensions, different header designs for logged-in/out users and works alongside the Beaver Builder and Elementor page builders. Our other plugins In addition to Ultimate Member, we also have two other plugins: ForumWP and JobBoardWP. ForumWP ForumWP is a forum plugin which adds an online forum to your website, allowing users to create topics and write replies. Forums are a great way to build and grow an online community. JobBoardWP JobBoardWP is a job board plugin which adds a modern job board to your website. Display job listings and allow employers to submit and manage jobs all from the front-end. Development * Translations If you’re a developer and would like to contribute to the source code of the plugin you can do so via our GitHub Repository. Want to add a new language to Ultimate Member? Great! You can contribute via translate.wordpress.org. If you are a developer and you need to know the list of UM Hooks, make this via our Hooks Documentation or Hooks Documentation v2. If you are a developer and you need to know the structure of our code, make this via our Documentation API. Documentation & Support Got a problem or need help with Ultimate Member? Head over to our documentation and perform a search of the knowledge base. If you can’t find a solution to your issue then you can create a topic on the support forum.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C