Ultimate Member <= 2.11.1 - Reflected Cross-Site Scripting via Filter Parameters
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Minimum safe version
2.11.3
Update to 2.11.3 or later to address 90 fixable vulnerabilities
CVE-2026-39659
Ultimate Member <= 2.11.2 - Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag
CVE-2025-15064
CVE-2025-12492
CVE-2025-13220
CVE-2025-14081
CVE-2025-13217
CVE-2025-47691
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection
Ultimate Member <= 2.10.0 - Unauthenticated SQL Injection via search Parameter
CVE-2024-12276
Ultimate Member <= 2.9.1 - Unauthenticated SQL Injection
WordPress Ultimate Member Plugin <= 2.9.1 is vulnerable to Sensitive Data Exposure
CVE-2024-10528
CVE-2024-8520
CVE-2024-8519
CVE-2024-2765
CVE-2024-2123
CVE-2024-1071
WordPress Ultimate Member Plugin <= 2.6.8 is vulnerable to Cross Site Request Forgery (CSRF)
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.6.8 - Cross-Site Request Forgery
CVE-2023-3460
CVE-2023-31216
Ultimate Member < 1.0.84 - Authorization Bypass to Arbitrary File Upload/Delete
Ultimate Member 1.2.98 - 1.2.997 - Reflected Cross-Site Scripting
Ultimate Member <= 1.3.64 - Local File Inclusion
Ultimate Member <= 1.3.75 - Missing Authorization to Password Reset
Ultimate Member <= 1.3.83 - Shortcode Injection
Ultimate Member <= 2.0.21 - Arbitrary File Upload
Ultimate Member <= 2.0.21 - Cross-Site Scripting
Ultimate Member <= 2.0.32 - Cross-Site Request Forgery
Ultimate Member <= 2.0.45 - Low-Privileged Stored Cross-Site Scripting
Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.0.45 - Arbitrary File Deletion/Read
Ultimate Member <= 2.0.45 - Admin+ Stored Cross-Site Scripting
Ultimate Member <= 2.1.6 - Open Redirect
Ultimate Member <= 2.4.1 - Username Enumeration
Ultimate Member <= 2.4.0 - Subscriber+ Stored Cross-Site Scripting
WordPress Ultimate Member plugin <= 2.5.0 - Auth. Directory Traversal vulnerability
CVE-2022-3361
CVE-2022-3384
CVE-2022-3383
Ultimate Member <= 1.0.78 - Multiple Vulnerabilities
Ultimate Member 1.2.98-1.2.994 - Reflected Cross-Site Scripting (XSS)
Ultimate Member < 1.3.65 - Local File Inclusion
Ultimate Member < 1.3.76 - Unauthenticated Change Passwords
Ultimate Member < 2.0.22 - Unauthenticated Arbitrary File Upload
Ultimate Member < 2.0.22 - Authenticated Cross-Site Scripting (XSS)
wpscan.com
Ultimate Member < 2.0.46 - Multiple Vulnerabilities
Ultimate Member < 2.1.7 - Unauthenticated Open Redirect
WordPress Ultimate Member Plugin <= 1.0.78 - Multiple Vulnerabilities
WordPress Ultimate Member Plugin <= 1.2.994 - Cross Site Scripting
WordPress Ultimate Member Plugin <= 1.3.28 - Reflected Cross Site Scripting
CVE-2022-1208
WordPress Ultimate Member Plugin <= 1.3.64 - Local File Inclusion
WordPress Ultimate Member Plugin <= 1.3.75 - Unauthenticated Change Passwords
WordPress Ultimate Member plugin <= 2.0.21 - Unauthenticated Arbitrary File Upload vulnerability
WordPress Ultimate Member plugin <= 2.0.21 - Authenticated Cross-Site Scripting (XSS) vulnerability
WordPress Ultimate Member plugin <= 2.0.32 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Ultimate Member plugin <= 2.0.45 - Multiple vulnerabilities
WordPress Ultimate Member plugin <= 2.0.51 - Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities
WordPress Ultimate Member plugin <= 2.1.11 - Unauthenticated/Authenticated Privilege Escalation
CVE-2022-1209
CVE-2015-8354
CVE-2018-6944
CVE-2018-6943
CVE-2018-10234
CVE-2018-10233
Ultimate Member <= 2.0.3 - Unauthorized Image File Upload
Ultimate Member <= 2.0.3 - Directory Traversal
CVE-2018-0588
Ultimate Member <= 1.3.88 - Cross Site Scripting
CVE-2018-0590
CVE-2018-0589
CVE-2018-13136
CVE-2018-17866
WordPress Ultimate Member plugin <= 2.0.39 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2019-10270
CVE-2019-10271
CVE-2018-20965
CVE-2019-14947
CVE-2019-14946
WordPress Ultimate Member plugin <= 2.0.53 - Cross-Site Scripting (XSS) vulnerability
CVE-2015-9304
CVE-2016-10872
WordPress Ultimate Member plugin <= 2.1.2 - Insecure Direct Object Reference (IDOR) vulnerability
CVE-2020-36157
CVE-2020-36156
CVE-2020-36155
CVE-2020-36170
CVE-2021-24306