Skip to main content

Vendor archive

ultimatemember CVEs

Beta · best-effort

53 CVEs tagged to vendor ultimatemember6 Critical, 10 High, 37 Medium, 0 Low, 0 Unrated.

CVE-2021-24306

Published May 24, 2021

The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36157

Published Jan 4, 2021

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the rol…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-36156

Published Jan 4, 2021

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-36155

Published Jan 4, 2021

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parame…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6859

Published Jan 13, 2020

Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to chan…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10271

Published Jun 24, 2019

An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover picture modification. It is possible to modify the profile and c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10270

Published Jun 21, 2019

An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset pa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10673

Published Apr 3, 2019

A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract se…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17866

Published Oct 9, 2018

Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0590

Published May 14, 2018

Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0589

Published May 14, 2018

Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecifie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0588

Published May 14, 2018

Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecifi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0587

Published May 14, 2018

Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0586

Published May 14, 2018

Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0585

Published May 14, 2018

Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified ve…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10234

Published Apr 23, 2018

Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/ad…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10233

Published Apr 23, 2018

The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 53 CVEsPage 2 of 3