Skip to main content

Vendor/product archive

ultimatemember / ultimate_member CVEs

Beta · best-effort

37 CVEs tagged to ultimatemember / ultimate_member5 Critical, 6 High, 26 Medium, 0 Low, 0 Unrated.

CVE-2024-12276

Published Feb 21, 2025

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0318

Published Jan 18, 2025

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in al…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-0308

Published Jan 18, 2025

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection v…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-10528

Published Nov 21, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile pictu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8520

Published Oct 4, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8519

Published Oct 4, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2765

Published May 2, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1071

Published Mar 13, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sor…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-2123

Published Mar 13, 2024

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-3460

Published Jul 4, 2023

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create admin…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2022-3384

Published Nov 29, 2022

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts use…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3383

Published Nov 29, 2022

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accept…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3361

Published Nov 29, 2022

The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3966

Published Nov 13, 2022

A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_template of the file includes/core/cl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1208

Published Jun 13, 2022

The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pages due to insufficient input s…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1209

Published May 10, 2022

The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24306

Published May 24, 2021

The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36157

Published Jan 4, 2021

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the rol…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-36156

Published Jan 4, 2021

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-36155

Published Jan 4, 2021

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parame…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6859

Published Jan 13, 2020

Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to chan…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2