Ultimatemember develops a focused line of WordPress plugins centered around user profiles, membership management, and community features, with a vulnerability footprint concentrated in a small product portfolio that nonetheless operates across a large installed base. The vendor's exposure recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, path traversal, and SQL injection, reflecting the input-handling and access-control demands of web-facing membership and forum systems. A meaningful share of the vendor's vulnerabilities reach serious severity, and public exploit code has a moderate tendency to become available for these flaws, making timely patching of this widely adopted plugin important for WordPress administrators. Defenders should treat Ultimatemember advisories as broadly applicable to sites running its membership and community plugins and prioritize patching to reduce exposure to common web-application attack vectors. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ultimatemember over time
Signals from CVEs in this vendor scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1071CRITICAL The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sort | Mar 13, 2024 | 9.8 | 90 | NO | YES |
CVE-2023-3460CRITICAL The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create admini | Jul 4, 2023 | 9.8 | 85 | NO | YES |
CVE-2020-36155CRITICAL An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array paramet | Jan 4, 2021 | 9.8 | 44 | NO | YES |
CVE-2024-2123MEDIUM The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting | Mar 13, 2024 | 6.1 | 31 | NO | NO |
CVE-2020-36157CRITICAL An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role | Jan 4, 2021 | 9.8 | 31 | NO | NO |
CVE-2024-54367CRITICAL Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a through <= 2.1.0. | Dec 16, 2024 | 9.8 | 30 | NO | NO |
CVE-2019-10270HIGH An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset pas | Jun 21, 2019 | 8.8 | 28 | NO | NO |
CVE-2020-36156HIGH An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the p | Jan 4, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-10673HIGH A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sen | Apr 3, 2019 | 8.8 | 27 | NO | NO |
CVE-2024-8428HIGH The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, | Sep 6, 2024 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (55 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ultimatemember.
Media articles that mention a CVE ID that affects a product developed by Ultimatemember — matched by CVE ID, not by vendor name.