Skip to main content

Vendor archive

ultimatemember CVEs

Beta · best-effort

53 CVEs tagged to vendor ultimatemember6 Critical, 10 High, 37 Medium, 0 Low, 0 Unrated.

CVE-2024-12276

Published Feb 21, 2025

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0318

Published Jan 18, 2025

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in al…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-0308

Published Jan 18, 2025

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection v…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-54367

Published Dec 16, 2024

Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a through <= 2.1.0.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23715

Published Dec 9, 2024

Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11204

Published Dec 6, 2024

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 2.1.2 due…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10879

Published Dec 6, 2024

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10880

Published Nov 23, 2024

The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10528

Published Nov 21, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile pictu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8520

Published Oct 4, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8519

Published Oct 4, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8428

Published Sep 6, 2024

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2765

Published May 2, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1071

Published Mar 13, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sor…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-2123

Published Mar 13, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-3460

Published Jul 4, 2023

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create admin…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2022-4061

Published Dec 19, 2022

The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3384

Published Nov 29, 2022

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts use…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3383

Published Nov 29, 2022

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accept…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3361

Published Nov 29, 2022

The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3966

Published Nov 13, 2022

A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/cl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1208

Published Jun 13, 2022

The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input s…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1209

Published May 10, 2022

The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39329

Published Oct 19, 2021

The JobBoardWP WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 53 CVEsPage 1 of 3