Plugin Vulnerability Hub
Plugin 69 known issues Latest disclosed Feb 17, 2026

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin Vulnerabilities

Review known vulnerability records for the WordPress plugin Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin (`ultimate-member`), including severity, CVE references, affected versions, and patch status.

Known Records
69
High or Critical
23
Linked CVEs
53
Last Updated
Feb 18, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
69 records include a published patch path.
Severity Mix
10 critical and 13 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-1404
Ultimate Member <= 2.11.1 - Reflected Cross-Site Scripting via Filter Parameters

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11...

Published
Feb 17, 2026
Patched Release
2.11.2
Affected Versions
Versions up to 2.11.1
Next Step
Update to 2.11.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13220
Ultimate Member <= 2.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes in all versions up to, and including, 2.11.0 due to insuffici...

Published
Dec 20, 2025
Patched Release
2.11.1
Affected Versions
Versions up to 2.11.0
Next Step
Update to 2.11.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12492
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 - Unauthenticated Sensitive Information Exposure

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to t...

Published
Dec 19, 2025
Patched Release
2.11.1
Affected Versions
Versions up to 2.11.0
Next Step
Update to 2.11.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14081
Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Profile Privacy Setting Bypass

The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in the allowed fields list before the `required_perm` check is a...

Published
Dec 16, 2025
Patched Release
2.11.1
Affected Versions
Versions up to 2.11.0
Next Step
Update to 2.11.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13217
Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value'

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2.11.0. This is due to insuffici...

Published
Dec 16, 2025
Patched Release
2.11.1
Affected Versions
Versions up to 2.11.0
Next Step
Update to 2.11.1 or newer if supported.
Plugin High Patched: Yes CVE-2025-47691
Ultimate Member <= 2.10.3 - Authenticated (Administrator+) Arbitrary Function Call

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Arbitrary Function Calls in all versions up to, and including, 2.10.3. This is due to the plugin not properly restricting funct...

Published
May 07, 2025
Patched Release
2.10.4
Affected Versions
Versions up to 2.10.3
Next Step
Update to 2.10.4 or newer if supported.
Plugin High Patched: Yes
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to insufficient escaping on the u...

Published
Apr 16, 2025
Patched Release
2.10.2
Affected Versions
Versions up to 2.10.1
Next Step
Update to 2.10.2 or newer if supported.
Plugin High Patched: Yes CVE-2025-1702
Ultimate Member <= 2.10.0 - Unauthenticated SQL Injection via search Parameter

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to insufficient escaping o...

Published
Mar 04, 2025
Patched Release
2.10.1
Affected Versions
Versions up to 2.10.0
Next Step
Update to 2.10.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-12276
Ultimate Member <= 2.9.2 - Authenticated SQL Injection

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the user s...

Published
Feb 20, 2025
Patched Release
2.10.0
Affected Versions
Versions up to 2.9.2
Next Step
Update to 2.10.0 or newer if supported.
Plugin High Patched: Yes CVE-2025-0308
Ultimate Member <= 2.9.1 - Unauthenticated SQL Injection

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on t...

Published
Jan 17, 2025
Patched Release
2.9.2
Affected Versions
Versions up to 2.9.1
Next Step
Update to 2.9.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-0318
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes...

Published
Jan 17, 2025
Patched Release
2.9.2
Affected Versions
Versions up to 2.9.1
Next Step
Update to 2.9.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10528
Ultimate Member <= 2.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture Update

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and ajax_resize_image()...

Published
Nov 20, 2024
Patched Release
2.9.0
Affected Versions
Versions up to 2.8.9
Next Step
Update to 2.9.0 or newer if supported.