CVE-2026-96451
- EPSS 0.3%
- Veröffentlicht 03.10.2026 16:16:46
- Zuletzt bearbeitet 06.10.2026 15:04:25
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
CVE-2026-93428
- EPSS 0.4%
- Veröffentlicht 03.10.2026 02:25:36
- Zuletzt bearbeitet 06.10.2026 15:04:52
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not p...
CVE-2026-96270
- EPSS 0.25%
- Veröffentlicht 03.10.2026 02:25:34
- Zuletzt bearbeitet 06.10.2026 15:04:52
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 2.1...
CVE-2026-62059
- EPSS 0.28%
- Veröffentlicht 01.10.2026 12:39:49
- Zuletzt bearbeitet 01.10.2026 14:34:35
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.
CVE-2026-15290
- EPSS 0.39%
- Veröffentlicht 10.07.2026 04:31:23
- Zuletzt bearbeitet 10.07.2026 17:16:53
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to ...
CVE-2026-7761
- EPSS 0.51%
- Veröffentlicht 24.06.2026 06:49:37
- Zuletzt bearbeitet 25.06.2026 13:26:11
The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.11.4. This is due to a chain of three logic bugs: (1) an MD5 hash fallback in get_directory_by_hash() ...
CVE-2026-39659
- EPSS 0.02%
- Veröffentlicht 08.04.2026 08:30:36
- Zuletzt bearbeitet 21.04.2026 11:16:19
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-15064
- EPSS 0.27%
- Veröffentlicht 04.04.2026 07:41:56
- Zuletzt bearbeitet 24.07.2026 22:10:00
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, ...
CVE-2025-13220
- EPSS 0.24%
- Veröffentlicht 21.12.2025 03:20:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes in all versions up to, and incl...
CVE-2025-12492
- EPSS 0.51%
- Veröffentlicht 20.12.2025 08:22:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_memb...