Vulnerabilities in ultimatemember

27 results
CVE-2024-1071CRITICALThe Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vEPSS 89.4%CVE-2024-2123HIGHUltimate Member <= 2.8.3 - Unauthenticated Stored Cross-Site ScriptingEPSS 26.7%CVE-2022-3383HIGHUltimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Remote Code Execution via Multi-SelectEPSS 2.8%CVE-2022-3384HIGHUltimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Limited Remote Code Execution via um_populate_dropdown_optionsEPSS 2.7%CVE-2022-3361MEDIUMUltimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Contributor+) Directory Traversal via ShortcodesEPSS 2.5%CVE-2022-1208MEDIUMUltimate Member <= 2.3.2 - Stored Cross-Site ScriptingEPSS 0.9%CVE-2022-1209MEDIUMUltimate Member <= 2.3.1 - Arbitrary RedirectEPSS 0.7%CVE-2025-1702HIGHUltimate Member <= 2.10.0 - Unauthenticated SQL Injection via search ParameterEPSS 0.7%CVE-2024-10528MEDIUMUltimate Member <= 2.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture UpdateEPSS 0.6%CVE-2025-0308HIGHUltimate Member <= 2.9.1 - Unauthenticated SQL InjectionEPSS 0.5%CVE-2024-2765MEDIUMUltimate Member <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-8428HIGHForumWP – Forum & Discussion Board Plugin <= 2.0.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via Account TakeoverEPSS 0.5%CVE-2024-10880MEDIUMJobBoardWP – Job Board Listings and Submissions <= 1.3.0 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2025-12492MEDIUMUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2024-8519MEDIUMUltimate Member <= 2.8.6 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2024-10879MEDIUMForumWP – Forum & Discussion Board <= 2.1.2 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2025-0318MEDIUMUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information ExposureEPSS 0.3%CVE-2024-11204MEDIUMForumWP – Forum & Discussion Board <= 2.1.2 - Reflected Cross-Site Scripting via url ParameterEPSS 0.3%CVE-2024-12276MEDIUMUltimate Member <= 2.9.2 - Authenticated SQL InjectionEPSS 0.3%CVE-2024-8520MEDIUMUltimate Member <= 2.8.6 - Cross-Site Request Forgery to Membership Status ChangeEPSS 0.3%