📦 Ultimate Member

by Ultimatemember

🔍 What is Ultimate Member?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-1071

CRITICAL CVSS 9.8 Mar 13, 2024

This SQL injection vulnerability in the Ultimate Member WordPress plugin allows unauthenticated attackers to inject malicious SQL queries through the 'sorting' parameter. Attackers can extract sensiti...

CVE-2023-3460

CRITICAL CVSS 9.8 Jul 4, 2023

The Ultimate Member WordPress plugin before version 2.6.7 contains a critical vulnerability that allows unauthenticated attackers to create user accounts with administrator privileges. This affects al...

CVE-2025-0308

HIGH CVSS 7.5 Jan 18, 2025

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks against WordPress sites using the Ultimate Member plugin. Attackers can extract sensitive information fr...

CVE-2024-2123

HIGH CVSS 7.2 Mar 13, 2024

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress pages using the Ultimate Member plugin. When users visit compromised pages, the scripts execute in their ...

CVE-2025-0318

MEDIUM CVSS 5.3 Jan 18, 2025

The Ultimate Member WordPress plugin versions up to 2.9.1 leak sensitive user metadata through error messages. Unauthenticated attackers can extract data from the wp_usermeta table, potentially exposi...

CVE-2024-10528

MEDIUM CVSS 4.3 Nov 21, 2024

This vulnerability in the Ultimate Member WordPress plugin allows authenticated attackers with subscriber-level access or higher to change other users' profile pictures without authorization. The flaw...

CVE-2024-8520

MEDIUM CVSS 5.3 Oct 4, 2024

This CSRF vulnerability in the Ultimate Member WordPress plugin allows unauthenticated attackers to modify user membership statuses by tricking administrators into clicking malicious links. All WordPr...

CVE-2024-2765

MEDIUM CVSS 5.4 May 2, 2024

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to inject malicious scripts into Skype and Spotify URL fields in the Ultimate Member plugin. The scripts ...