Ultimate member
This hub aggregates every CVE we track for Ultimate member, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
43
CVEs tracked
5
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM31HIGH7CRITICAL5
Monthly trend
0
0
0
2
1
0
2
1
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Ultimate member.
- CVE-2025-47691WordPress Ultimate Member plugin <= 2.10.3 - Arbitrary Function Call vulnerability5.5
- CVE-2024-12276Ultimate Member <= 2.9.2 - Authenticated SQL Injection5.3
- CVE-2025-0308Ultimate Member <= 2.9.1 - Unauthenticated SQL Injection7.5
- CVE-2025-0318Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure5.3
- CVE-2024-10528Ultimate Member <= 2.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture Update4.3
- CVE-2024-8519Ultimate Member <= 2.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
- CVE-2024-8520Ultimate Member <= 2.8.6 - Cross-Site Request Forgery to Membership Status Change5.3
- CVE-2024-2765Ultimate Member <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting5.4
- CVE-2024-1071The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter ...9.8
- CVE-2024-2123Ultimate Member <= 2.8.3 - Unauthenticated Stored Cross-Site Scripting7.2
- CVE-2023-31216WordPress Ultimate Member Plugin <= 2.6.0 is vulnerable to Cross Site Request Forgery (CSRF)4.3
- CVE-2023-3460Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation9.8
- CVE-2022-3383Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Remote Code Execution via Multi-Select7.2
- CVE-2022-3384Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Limited Remote Code Execution via um_populate_dropdown_options7.2
- CVE-2022-3361Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Contributor+) Directory Traversal via Shortcodes4.3
Product normalization is registry-driven with AI assist and human review. How it works