Ultimatemember

Ultimatemember

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 08.04.2026 08:30:36
  • Zuletzt bearbeitet 09.04.2026 16:16:30

Missing Authorization vulnerability in Ultimate Member Ultimate Member ultimate-member allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Member: from n/a through <= 2.11.3.

  • EPSS 0.01%
  • Veröffentlicht 04.04.2026 07:41:56
  • Zuletzt bearbeitet 07.04.2026 13:20:55

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, ...

  • EPSS 0.06%
  • Veröffentlicht 21.12.2025 03:20:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes in all versions up to, and incl...

  • EPSS 0.07%
  • Veröffentlicht 20.12.2025 08:22:10
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_memb...

  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 18:21:35
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in the allowed fields list before ...

  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 18:21:34
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2....

  • EPSS 0.14%
  • Veröffentlicht 07.05.2025 14:20:57
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3.

  • EPSS 2.17%
  • Veröffentlicht 05.03.2025 12:15:35
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 ...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 16.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:11:27

core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.