← WordPress Vulnerabilities
WordPress security by component

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is a WordPress component with 56 published CVE records in this archive. The latest tracked vulnerability was published Jul 10, 2026; the highest CVE/CNA score is 10.

Plugin slug: ultimate-member

CVE-2026-15290: Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.10.1.

PublishedJul 10, 2026
Known safe version> 2.10.1
Safe version
Jul 10, 2026 CVE-2026-15290
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 2.10.1.
> 2.10.1
CVE7.5
NVDPending
Jul 06, 2026 CVE-2026-11766
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.12.0.
2.12.0
CVE8.0
NVDPending
Jul 03, 2026 CVE-2026-8489
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.11.4.
> 2.11.4
CVE6.4
NVDPending
Jun 24, 2026 CVE-2026-7761
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Privilege escalation or authentication bypass
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.11.4.
> 2.11.4
CVE8.8
NVDPending
May 13, 2026 CVE-2020-37169
ultimate-member: Filesystem traversal
ultimate-member is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is 2.1.3.
See mitigation notes
CVE6.8
NVDPending
Mar 27, 2026 CVE-2026-4248
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Privilege escalation or authentication bypass
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.11.2.
> 2.11.2
CVE8.0
NVDPending
Feb 18, 2026 CVE-2026-1404
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Dec 21, 2025 CVE-2025-13220
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Dec 20, 2025 CVE-2025-12492
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Sensitive information exposure
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Dec 17, 2025 CVE-2025-14081
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 17, 2025 CVE-2025-13217
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
May 07, 2025 CVE-2025-47691
Ultimate Member: Code execution
Ultimate Member is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE5.5
NVDPending
Mar 05, 2025 CVE-2025-1702
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Feb 21, 2025 CVE-2024-12276
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE5.3
NVD6.5
Jan 18, 2025 CVE-2025-0318
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: A security weakness
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 18, 2025 CVE-2025-0308
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Nov 21, 2024 CVE-2024-10528
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: A security weakness
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Oct 04, 2024 CVE-2024-8520
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site request forgery
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.3
NVD4.3
Oct 04, 2024 CVE-2024-8519
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2765
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Mar 13, 2024 CVE-2024-1071
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: SQL injection
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVDPending
Mar 13, 2024 CVE-2024-2123
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Jul 17, 2023 CVE-2023-31216
Ultimate Member: Cross-site request forgery
Ultimate Member is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Jul 04, 2023 CVE-2023-3460
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Nov 29, 2022 CVE-2022-3384
Ultimate Member: Code execution
Ultimate Member is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVD7.2
Nov 29, 2022 CVE-2022-3383
Ultimate Member: Code execution
Ultimate Member is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVD7.2
Nov 29, 2022 CVE-2022-3361
Ultimate Member: Filesystem traversal
Ultimate Member is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.3
NVD4.3
Jun 13, 2022 CVE-2022-1208
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 10, 2022 CVE-2022-1209
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD5.4
May 24, 2021 CVE-2021-24306
Ultimate Member – User Profile, User Registration, Login & Membership Plugin: Cross-site scripting
Ultimate Member – User Profile, User Registration, Login & Membership Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jan 06, 2021 CVE-2020-36170
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Jan 04, 2021 CVE-2020-36157
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE10.0
NVD9.8
Jan 04, 2021 CVE-2020-36156
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.9
NVD8.8
Jan 04, 2021 CVE-2020-36155
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE10.0
NVD9.8
Jan 13, 2020 CVE-2020-6859
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Aug 12, 2019 CVE-2019-14947
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 12, 2019 CVE-2019-14946
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 12, 2019 CVE-2019-14945
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 12, 2019 CVE-2018-20965
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 12, 2019 CVE-2016-10872
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 12, 2019 CVE-2015-9304
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jun 24, 2019 CVE-2019-10271
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Jun 21, 2019 CVE-2019-10270
Ultimate Member: Privilege escalation or authentication bypass
Ultimate Member is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8
Apr 03, 2019 CVE-2019-10673
profile edit form in the Ultimate Member: Cross-site request forgery
profile edit form in the Ultimate Member is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Oct 09, 2018 CVE-2018-17866
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jul 04, 2018 CVE-2018-13136
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
May 14, 2018 CVE-2018-0590
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
May 14, 2018 CVE-2018-0589
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
May 14, 2018 CVE-2018-0588
Ultimate Member: Filesystem traversal
Ultimate Member is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVD7.5
May 14, 2018 CVE-2018-0587
Ultimate Member: A security weakness
Ultimate Member is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
May 14, 2018 CVE-2018-0586
Ultimate Member: Filesystem traversal
Ultimate Member is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.3
NVD4.3
May 14, 2018 CVE-2018-0585
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Apr 23, 2018 CVE-2018-10234
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Apr 23, 2018 CVE-2018-10233
Ultimate Member: Cross-site request forgery
Ultimate Member is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Feb 16, 2018 CVE-2018-6944
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Sep 11, 2017 CVE-2015-8354
Ultimate Member: Cross-site scripting
Ultimate Member is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1