CVE-2026-25357
Ultimate Membership Pro
Minimum safe version
13.7.1
Update to 13.7.1 or later to address 18 fixable vulnerabilities
CVE-2020-36832
CVE-2020-36833
CVE-2024-43240
CVE-2024-43241
CVE-2024-43242
Ultimate Membership Pro 7.4.2 <= 7.5 - Arbitrary media include
Ultimate Membership Pro <= 7.5 - Arbitrary media upload
Ultimate Membership Pro < 8.6.1 - Multiple Critical Vulnerabilities
Ultimate Membership Pro < 8.7 - Cross-Site Request Forgery allowing Arbitrary Account Deletion and Creation
Ultimate Membership Pro < 8.6.2 - Multiple CSRF Issues via AJAX Calls, Insufficient Filename Entropy
Indeed Membership Pro <= 7.5 - Arbitrary File Upload
Indeed Membership Pro <= 7.5 - Remote Image File Inclusion
Indeed Membership Pro 7.3 - 8.6 - Missing Authorization Checks
Indeed Membership Pro 7.3 - 8.6 - Authentication Bypass
Ultimate Membership Pro <= 8.6.1 - Cross-Site Request Forgery
Ultimate Membership Pro <= 8.6 - Cross-Site Request Forgery
Ultimate Membership Pro plugin <= 8.6 - Multiple Critical Vulnerabilities
WordPress Ultimate Membership Pro premium plugin <= 8.6 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Ultimate Membership Pro premium plugin <= 8.6.1 - Multiple Cross-Site Scripting (CSRF) vulnerabilities