Ultimate Member

WordPress plugin · ultimate-member · WordPress.org ↗
0
Critical
4
High
6
Known total
1
Unfixed
Running Ultimate Member on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 8.8
Ultimate Member < 2.13.1 - Unauthenticated Stored XSS via Profile Page Title
CVE.org
>=0, <2.13.1 v2.13.1 CVE-2026-85680 Sep 19, 2026
HIGH
CVSS 8.1
Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms
CVE.org
>=2.6.7, <2.13.0 v2.13.0 CVE-2026-19423 Aug 28, 2026
HIGH
CVSS 8.1
Ultimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Selection Field
CVE.org
>=0, <2.12.1 v2.12.1 CVE-2026-12251 Jul 31, 2026
HIGH
CVSS 8.0
Ultimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile Fields
CVE.org
>=0, <2.12.0 v2.12.0 CVE-2026-11766 Jul 6, 2026
MEDIUM
CVSS 5.3
Ultimate Member < 2.13.0 - Unauthenticated Unapproved Comment Disclosure via Profile Activity
CVE.org
>=0, <2.13.0 v2.13.0 CVE-2026-19251 Sep 2, 2026
MEDIUM
CVSS 6.8
WordPress Plugin ultimate-member 2.1.3 Local File Inclusion
CVE.org
2.1.3 unfixed CVE-2020-37169 May 13, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.