← WordPress Vulnerabilities
WordPress security by component

Ultimate Member

Ultimate Member adds user registration, login, profiles, directories, and membership-related account pages to WordPress.

Ultimate Member (ultimate-member) is a WordPress plugin with 60 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 10.

Plugin slug: ultimate-member

CVE-2026-19251: Ultimate Member exposes unapproved comments through profile activity

Ultimate Member before 2.13.0 does not check comment approval or profile privacy before returning profile activity. An unauthenticated visitor can read comments that are still awaiting moderation, including activity belonging to private profiles.

PublishedSep 02, 2026
Known safe version2.13.0
Published vulnerabilities for ultimate-member
Safe version
Sep 02, 2026 CVE-2026-19251
Ultimate Member exposes unapproved comments through profile activity
Ultimate Member before 2.13.0 does not check comment approval or profile privacy before returning profile activity. An unauthenticated visitor can read comments that are still awaiting moderation, including activity belonging to private profiles.
2.13.0
CVE5.3
NVDPending
Aug 28, 2026 CVE-2026-19423
Ultimate Member registration permits administrator-equivalent capability assignment
Ultimate Member 2.6.7 through 2.12.x validates a submitted registration role against all registered site roles when it cannot resolve the form's own allow-list. An unauthenticated registrant can select a role with arbitrary capabilities and reach administrator-equivalent access.
2.13.0
CVE8.1
NVDPending
Aug 25, 2026 CVE-2026-18547
Ultimate Member permits Subscriber-level stored cross-site scripting
Ultimate Member through 2.12.1 lets a Subscriber store a quote-breakout payload in the id attribute of an HTML-enabled textarea profile field. The allowed div attribute survives wp_kses processing, then pickadate.js concatenates the stored id into HTML through jQuery .html(), allowing autofocus and onfocus syntax to execute JavaScript when the profile loads.
2.13.0
CVE6.4
NVDPending
Jul 31, 2026 CVE-2026-12251
Ultimate Member registration can assign a site-defined administrator role
Ultimate Member before 2.12.1 does not remove administrator-level capabilities from roles made selectable on registration forms, and its post-registration safeguard against elevated accounts is disabled by default. If a published registration form includes a role-selection field and the site has a custom role carrying administrator capabilities, an unauthenticated visitor can choose that role during registration and receive administrative access. The published.
2.12.1
CVE8.1
NVDPending
Jul 10, 2026 CVE-2026-15290
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.10.1.
See mitigation notes
CVE7.5
NVDPending
Jul 06, 2026 CVE-2026-11766
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.12.0.
2.12.0
CVE8.0
NVDPending
Jul 03, 2026 CVE-2026-8489
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.11.4.
2.12.1
CVE6.4
NVDPending
Jun 24, 2026 CVE-2026-7761
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Privilege escalation or authentication bypass
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated contributor account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.11.4.
2.12.1
CVE8.8
NVDPending
May 13, 2026 CVE-2020-37169
ultimate-member: Filesystem traversal
ultimate-member is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is 2.1.3.
See mitigation notes
CVE6.8
NVDPending
Mar 27, 2026 CVE-2026-4248
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Privilege escalation or authentication bypass
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated contributor account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.11.2.
2.12.1
CVE8.0
NVDPending
Feb 18, 2026 CVE-2026-1404
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Dec 21, 2025 CVE-2025-13220
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Dec 20, 2025 CVE-2025-12492
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Sensitive information exposure
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Dec 17, 2025 CVE-2025-14081
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 17, 2025 CVE-2025-13217
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
May 07, 2025 CVE-2025-47691
Ultimate Member: Code execution
Ultimate Member is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE5.5
NVDPending
Mar 05, 2025 CVE-2025-1702
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Feb 21, 2025 CVE-2024-12276
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE5.3
NVD6.5
Jan 18, 2025 CVE-2025-0318
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: A security weakness
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 18, 2025 CVE-2025-0308
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Nov 21, 2024 CVE-2024-10528
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: A security weakness
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Oct 04, 2024 CVE-2024-8520
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site request forgery
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.3
NVD4.3
Oct 04, 2024 CVE-2024-8519
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2765
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Mar 13, 2024 CVE-2024-1071
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVDPending
Mar 13, 2024 CVE-2024-2123
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Jul 17, 2023 CVE-2023-31216
Ultimate Member: Cross-site request forgery
Ultimate Member is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Jul 04, 2023 CVE-2023-3460
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD9.8
Nov 29, 2022 CVE-2022-3384
Ultimate Member: Code execution
Ultimate Member is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVD7.2
Nov 29, 2022 CVE-2022-3383
Ultimate Member: Code execution
Ultimate Member is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVD7.2
Nov 29, 2022 CVE-2022-3361
Ultimate Member: Filesystem traversal
Ultimate Member is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.3
NVD4.3
Jun 13, 2022 CVE-2022-1208
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 10, 2022 CVE-2022-1209
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD5.4
May 24, 2021 CVE-2021-24306
Ultimate Member – User Profile, User Registration, Login & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, User Registration, Login & Membership Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Jan 06, 2021 CVE-2020-36170
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.3
Jan 04, 2021 CVE-2020-36157
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE10.0
NVD9.8
Jan 04, 2021 CVE-2020-36156
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.9
NVD8.8
Jan 04, 2021 CVE-2020-36155
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE10.0
NVD9.8
Jan 13, 2020 CVE-2020-6859
Ultimate Member: Broken access control
Ultimate Member is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVEPending
NVD5.3
Aug 12, 2019 CVE-2019-14947
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Aug 12, 2019 CVE-2019-14946
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Aug 12, 2019 CVE-2019-14945
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Aug 12, 2019 CVE-2018-20965
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Aug 12, 2019 CVE-2016-10872
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Aug 12, 2019 CVE-2015-9304
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jun 24, 2019 CVE-2019-10271
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.3
Jun 21, 2019 CVE-2019-10270
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVEPending
NVD8.8
Apr 03, 2019 CVE-2019-10673
profile edit form in the Ultimate Member: Cross-site request forgery
profile edit form in the Ultimate Member is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD8.8
Oct 09, 2018 CVE-2018-17866
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jul 04, 2018 CVE-2018-13136
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
May 14, 2018 CVE-2018-0590
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.3
May 14, 2018 CVE-2018-0589
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.3
May 14, 2018 CVE-2018-0588
Ultimate Member: Filesystem traversal
Ultimate Member is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVEPending
NVD7.5
May 14, 2018 CVE-2018-0587
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.3
May 14, 2018 CVE-2018-0586
Ultimate Member: Filesystem traversal
Ultimate Member is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVEPending
NVD4.3
May 14, 2018 CVE-2018-0585
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Apr 23, 2018 CVE-2018-10234
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Apr 23, 2018 CVE-2018-10233
Ultimate Member: Cross-site request forgery
Ultimate Member is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD8.8
Feb 16, 2018 CVE-2018-6944
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Sep 11, 2017 CVE-2015-8354
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1