Ultimate membership pro
This hub aggregates every CVE we track for Ultimate membership pro, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
2
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting Ultimate membership pro.
- CVE-2026-25357WordPress Ultimate Membership Pro plugin <= 13.7 - Account Takeover vulnerability8.1
- CVE-2024-43242WordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Unauthenticated PHP Object Injection vulnerability9.0
- CVE-2024-43240WordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Unauthenticated Privilege Escalation vulnerability9.4
- CVE-2024-43241WordPress Indeed Ultimate Membership Pro plugin <= 12.7 - Reflected Cross Site Scripting (XSS) vulnerability7.1
Product normalization is registry-driven with AI assist and human review. How it works