Ultimate Member Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Ultimate Member products.
Products
- Ultimate Member8 vulnerabilities
- ForumWP2 vulnerabilities
- ultimate_member2 vulnerabilities
- Ultimate Member – User Profile, User Registration, Login & Membership Plugin1 vulnerability
- ultimate-member1 vulnerability
- User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37169MEDIUM | WordPress Plugin ultimate-member 2.1.3 Local File InclusionWordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP files from the packages directory and execute arbitrary code. CWE-98May 13, 2026 | CVSS6.8v4.0 | EPSS0.246% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67474MEDIUM | WordPress ForumWP plugin <= 2.1.4 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Ultimate Member ForumWP forumwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ForumWP: from n/a through <= 2.1.4. CWE-862Dec 9, 2025 | CVSS4.3v3.1 | EPSS0.225% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47691MEDIUM | WordPress Ultimate Member plugin <= 2.10.3 - Arbitrary Function Call vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3. CWE-94May 7, 2025 | CVSS5.5v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-54367CRITICAL | WordPress ForumWP plugin <= 2.1.0 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a through <= 2.1.0. CWE-502Dec 16, 2024 | CVSS9.8v3.1 | EPSS0.694% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2123HIGH | Ultimate Member <= 2.8.3 - Unauthenticated Stored Cross-Site ScriptingThe Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Mar 13, 2024 | CVSS7.2v3.1 | EPSS26.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-31216MEDIUM | WordPress Ultimate Member Plugin <= 2.6.0 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions. CWE-352Jul 17, 2023 | CVSS4.3v3.1 | EPSS0.271% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3460CRITICAL | Ultimate Member < 2.6.7 - Unauthenticated Privilege EscalationThe Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild. | CVSS9.8v3.1 | EPSS72.3% | PoCs10 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-24306MEDIUM | Ultimate Member < 2.1.20 - Authenticated Reflected Cross-Site Scripting (XSS)The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site Scripting issue. Knowledge of the targeted username is required to exploit this, and attackers would then need to make the related logged in user open a malicious link. CWE-79May 24, 2021 | CVSS5.4v3.1 | EPSS0.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36155CRITICAL | Ultimate Member ultimate_member Improper Privilege ManagementAn issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive metadata, such as the wp_capabilities user meta that defines a user's role. During the registration process, submitted registration details were passed to the update_profile function, and any metadata was accepted, e.g., wp_capabilities[administrator] for Administrator access. | CVSS10.0v3.1 | EPSS8.98% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-0589MEDIUM | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors. May 14, 2018 | CVSS4.3v3.0 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0587MEDIUM | Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors. CWE-434May 14, 2018 | CVSS4.3v3.0 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0588HIGH | Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors. CWE-22May 14, 2018 | CVSS7.5v3.0 | EPSS2.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0590MEDIUM | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors. May 14, 2018 | CVSS4.3v3.0 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0586MEDIUM | Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors. CWE-22May 14, 2018 | CVSS4.3v3.0 | EPSS1.61% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0585MEDIUM | Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79May 14, 2018 | CVSS5.4v3.0 | EPSS0.998% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |