Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2022; 10 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 8.5, and the most serious one scores 9.8 out of 10. Severity breakdown: 4 critical and 6 high. 2015 was the busiest year with 8 disclosures.

The most common weakness is SQL Injection, behind 8 of the records (67%). Other recurring categories include Cross-Site Scripting, Cross-Site Request Forgery (CSRF).

10 of the records (83%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2014.

4 independent researchers contributed these findings, most of them (6) reported by Panagiotis Vagenas.

01234567891029.09.2014Today29.09.20148.8Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 3.1.0 - SQL Injection CVSS 8.8 · 29.09.201422.10.20149.8Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.3.58 - SQL Injection CVSS 9.8 · 22.10.20149.8Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.3.58 - SQL Injection CVSS 9.8 · 22.10.201409.02.20158.8Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.4.36 - SQL Injection CVSS 8.8 · 09.02.201517.04.20157.2Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.4.95 - SQL Injection CVSS 7.2 · 17.04.201504.06.20159.8Users Ultra <= 1.5.15 - Multiple SQL Injection CVSS 9.8 · 04.06.201517.11.20158.8Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.5.58 - Arbitrary File Upload CVSS 8.8 · 17.11.201501.12.20158.8Users Ultra Membership Plugin <= 1.5.63 - Authenticated Blind SQL Injection CVSS 8.8 · 01.12.201502.12.20155.4Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.5.63 - Cross-Site Scripting via p_name parameter CVSS 5.4 · 02.12.20158.8Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.5.63 - Cross-Site Request Forgery CVSS 8.8 · 02.12.20156.1Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.5.63 - Cross-Site Scripting CVSS 6.1 · 02.12.201513.04.20229.8Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 3.1.0 - Unauthenticated SQL Injection CVSS 9.8 · 13.04.2022

Strategic Overview

Avg CVSSHigh
8.5/ 10
Patch Coverage83%
Open

2

Fixed

10

Get automatic notifications for all Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2022-0769

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 3.1.0 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

12 records
2022-04-13 00:00CVE-2022-0769
9.8
Critical
cydaveNo
2015-12-02 00:00CVE-2015-9392
5.4
Medium
Panagiotis VagenasYes
2015-12-02 00:00CVE-2015-9394
8.8
High
Panagiotis VagenasYes
2015-12-02 00:00CVE-2015-9393
6.1
Medium
Panagiotis VagenasYes
2015-12-01 00:00CVE-2015-9395
8.8
High
Panagiotis VagenasYes
2015-11-17 00:00CVE-2015-9402
8.8
High
Panagiotis VagenasYes
2015-06-04 00:00CVE-2015-4109
9.8
Critical
Panagiotis VagenasYes
2015-04-17 00:00N/A
7.2
High
AnonymousYes
2015-02-09 00:00N/A
8.8
High
James HookerYes
2014-10-22 00:00N/A
9.8
Critical
AnonymousYes
Showing 1–10 of 12 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C