WordPress security by component
Ultimate Member
Plugin description
Ultimate Member adds user registration, login, profiles, directories, and membership-related account pages to WordPress.
Ultimate Member (ultimate-member) is a WordPress plugin with 60 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 10.
Plugin slug:
ultimate-memberLatest vulnerability
CVE-2026-19251: Ultimate Member exposes unapproved comments through profile activity
Ultimate Member before 2.13.0 does not check comment approval or profile privacy before returning profile activity. An unauthenticated visitor can read comments that are still awaiting moderation, including activity belonging to private profiles.
| Safe version |
|
||
|---|---|---|---|
| Sep 02, 2026 |
CVE-2026-19251
Ultimate Member exposes unapproved comments through profile activity
Ultimate Member before 2.13.0 does not check comment approval or profile privacy before returning profile activity. An unauthenticated visitor can read comments that are still awaiting moderation, including activity belonging to private profiles.
|
2.13.0 |
CVE5.3
NVDPending
|
| Aug 28, 2026 |
CVE-2026-19423
Ultimate Member registration permits administrator-equivalent capability assignment
Ultimate Member 2.6.7 through 2.12.x validates a submitted registration role against all registered site roles when it cannot resolve the form's own allow-list. An unauthenticated registrant can select a role with arbitrary capabilities and reach administrator-equivalent access.
|
2.13.0 |
CVE8.1
NVDPending
|
| Aug 25, 2026 |
CVE-2026-18547
Ultimate Member permits Subscriber-level stored cross-site scripting
Ultimate Member through 2.12.1 lets a Subscriber store a quote-breakout payload in the id attribute of an HTML-enabled textarea profile field. The allowed div attribute survives wp_kses processing, then pickadate.js concatenates the stored id into HTML through jQuery .html(), allowing autofocus and onfocus syntax to execute JavaScript when the profile loads.
|
2.13.0 |
CVE6.4
NVDPending
|
| Jul 31, 2026 |
CVE-2026-12251
Ultimate Member registration can assign a site-defined administrator role
Ultimate Member before 2.12.1 does not remove administrator-level capabilities from roles made selectable on registration forms, and its post-registration safeguard against elevated accounts is disabled by default. If a published registration form includes a role-selection field and the site has a custom role carrying administrator capabilities, an unauthenticated visitor can choose that role during registration and receive administrative access. The published.
|
2.12.1 |
CVE8.1
NVDPending
|
| Jul 10, 2026 |
CVE-2026-15290
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.10.1.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jul 06, 2026 |
CVE-2026-11766
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.12.0.
|
2.12.0 |
CVE8.0
NVDPending
|
| Jul 03, 2026 |
CVE-2026-8489
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.11.4.
|
2.12.1 |
CVE6.4
NVDPending
|
| Jun 24, 2026 |
CVE-2026-7761
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Privilege escalation or authentication bypass
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated contributor account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.11.4.
|
2.12.1 |
CVE8.8
NVDPending
|
| May 13, 2026 |
CVE-2020-37169
ultimate-member: Filesystem traversal
ultimate-member is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is 2.1.3.
|
See mitigation notes |
CVE6.8
NVDPending
|
| Mar 27, 2026 |
CVE-2026-4248
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Privilege escalation or authentication bypass
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated contributor account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.11.2.
|
2.12.1 |
CVE8.0
NVDPending
|
| Feb 18, 2026 |
CVE-2026-1404
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Dec 21, 2025 |
CVE-2025-13220
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Dec 20, 2025 |
CVE-2025-12492
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Sensitive information exposure
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 17, 2025 |
CVE-2025-14081
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 17, 2025 |
CVE-2025-13217
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 07, 2025 |
CVE-2025-47691
Ultimate Member: Code execution
Ultimate Member is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE5.5
NVDPending
|
| Mar 05, 2025 |
CVE-2025-1702
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Feb 21, 2025 |
CVE-2024-12276
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE5.3
NVD6.5
|
| Jan 18, 2025 |
CVE-2025-0318
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: A security weakness
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 18, 2025 |
CVE-2025-0308
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Nov 21, 2024 |
CVE-2024-10528
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: A security weakness
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 04, 2024 |
CVE-2024-8520
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site request forgery
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.3
NVD4.3
|
| Oct 04, 2024 |
CVE-2024-8519
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-2765
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-1071
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Mar 13, 2024 |
CVE-2024-2123
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Jul 17, 2023 |
CVE-2023-31216
Ultimate Member: Cross-site request forgery
Ultimate Member is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Jul 04, 2023 |
CVE-2023-3460
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD9.8
|
| Nov 29, 2022 |
CVE-2022-3384
Ultimate Member: Code execution
Ultimate Member is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Nov 29, 2022 |
CVE-2022-3383
Ultimate Member: Code execution
Ultimate Member is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Nov 29, 2022 |
CVE-2022-3361
Ultimate Member: Filesystem traversal
Ultimate Member is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jun 13, 2022 |
CVE-2022-1208
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 10, 2022 |
CVE-2022-1209
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD5.4
|
| May 24, 2021 |
CVE-2021-24306
Ultimate Member – User Profile, User Registration, Login & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, User Registration, Login & Membership Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Jan 06, 2021 |
CVE-2020-36170
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.3
|
| Jan 04, 2021 |
CVE-2020-36157
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE10.0
NVD9.8
|
| Jan 04, 2021 |
CVE-2020-36156
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.9
NVD8.8
|
| Jan 04, 2021 |
CVE-2020-36155
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE10.0
NVD9.8
|
| Jan 13, 2020 |
CVE-2020-6859
Ultimate Member: Broken access control
Ultimate Member is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVEPending
NVD5.3
|
| Aug 12, 2019 |
CVE-2019-14947
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Aug 12, 2019 |
CVE-2019-14946
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Aug 12, 2019 |
CVE-2019-14945
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Aug 12, 2019 |
CVE-2018-20965
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Aug 12, 2019 |
CVE-2016-10872
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Aug 12, 2019 |
CVE-2015-9304
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jun 24, 2019 |
CVE-2019-10271
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD4.3
|
| Jun 21, 2019 |
CVE-2019-10270
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Apr 03, 2019 |
CVE-2019-10673
profile edit form in the Ultimate Member: Cross-site request forgery
profile edit form in the Ultimate Member is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Oct 09, 2018 |
CVE-2018-17866
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jul 04, 2018 |
CVE-2018-13136
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| May 14, 2018 |
CVE-2018-0590
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD4.3
|
| May 14, 2018 |
CVE-2018-0589
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD4.3
|
| May 14, 2018 |
CVE-2018-0588
Ultimate Member: Filesystem traversal
Ultimate Member is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD7.5
|
| May 14, 2018 |
CVE-2018-0587
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD4.3
|
| May 14, 2018 |
CVE-2018-0586
Ultimate Member: Filesystem traversal
Ultimate Member is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD4.3
|
| May 14, 2018 |
CVE-2018-0585
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Apr 23, 2018 |
CVE-2018-10234
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Apr 23, 2018 |
CVE-2018-10233
Ultimate Member: Cross-site request forgery
Ultimate Member is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Feb 16, 2018 |
CVE-2018-6944
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Sep 11, 2017 |
CVE-2015-8354
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|