Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ultimatemember

First CVE: Sep 11, 2017Active for: 9 yearsTotal CVEs: 55
35.5
VTI Score
Medium

Ultimatemember develops a focused line of WordPress plugins centered around user profiles, membership management, and community features, with a vulnerability footprint concentrated in a small product portfolio that nonetheless operates across a large installed base. The vendor's exposure recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, path traversal, and SQL injection, reflecting the input-handling and access-control demands of web-facing membership and forum systems. A meaningful share of the vendor's vulnerabilities reach serious severity, and public exploit code has a moderate tendency to become available for these flaws, making timely patching of this widely adopted plugin important for WordPress administrators. Defenders should treat Ultimatemember advisories as broadly applicable to sites running its membership and community plugins and prioritize patching to reduce exposure to common web-application attack vectors. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
55
Total CVEs
More Total CVEs than 99% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ultimatemember over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2017
8 years ago
Most Recent CVE
Dec 9, 2025
227 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-1071CRITICAL
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sort
Mar 13, 20249.890NOYES
CVE-2023-3460CRITICAL
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create admini
Jul 4, 20239.885NOYES
CVE-2020-36155CRITICAL
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array paramet
Jan 4, 20219.844NOYES
CVE-2024-2123MEDIUM
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting
Mar 13, 20246.131NONO
CVE-2020-36157CRITICAL
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role
Jan 4, 20219.831NONO
CVE-2024-54367CRITICAL
Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a through <= 2.1.0.
Dec 16, 20249.830NONO
CVE-2019-10270HIGH
An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset pas
Jun 21, 20198.828NONO
CVE-2020-36156HIGH
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the p
Jan 4, 20218.827NONO
CVE-2019-10673HIGH
A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sen
Apr 3, 20198.827NONO
CVE-2024-8428HIGH
The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including,
Sep 6, 20248.826NONO
View all 55 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products55 CVEs
67%
24%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network55 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (98.2%)
High1 (1.8%)
Unknown0 (0.0%)
User Interaction
None28 (50.9%)
Unknown0 (0.0%)
Required27 (49.1%)
Privileges Required
Low22 (40.0%)
High5 (9.1%)
None28 (50.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 97th percentile
Nuclei
3 CVEs
5.5% of CVEs· 96th percentile
ExploitDB
1 CVE
1.8% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ultimatemember.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ultimatemember — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ultimatemember's Products

View all 6 CNAs →

Top CWEs