Ultimatemember
Ultimatemember Ultimate Member: vulnerabilidades y CVE
Ultimatemember Ultimate Member tiene 56 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE56
Últimos 12 meses17
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-62059 | Alta (7.6) | 0.28% | — | 1 oct 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from… |
| CVE-2026-85680 | Alta (8.8) | 0.51% | — | 19 sept 2026 | The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has… |
| CVE-2026-19251 | Media (5.3) | 0.23% | — | 2 sept 2026 | The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors,… |
| CVE-2026-19423 | Alta (8.1) | 0.23% | — | 28 ago 2026 | The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role… |
| CVE-2026-18547 | Media (6.4) | 0.28% | — | 25 ago 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Textarea Profile Field with HTML… |
| CVE-2026-12251 | Alta (8.1) | 0.38% | — | 31 jul 2026 | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated… |
| CVE-2026-15290 | Alta (7.5) | 0.51% | — | 10 jul 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up… |
| CVE-2026-11766 | Alta (8) | 0.41% | — | 6 jul 2026 | The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with… |
| CVE-2026-8489 | Media (6.4) | 0.42% | — | 3 jul 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all… |
| CVE-2026-7761 | Alta (8.8) | 0.72% | — | 24 jun 2026 | The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.11.4. This is due to a chain of three logic bugs: (1) an MD5 hash… |
| CVE-2025-15064 | Media (6.4) | 0.27% | — | 4 abr 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all… |
| CVE-2026-4248 | Alta (8) | 0.42% | — | 27 mar 2026 | The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed… |
| CVE-2026-1404 | Media (6.1) | 0.22% | — | 18 feb 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g.,… |
| CVE-2025-13220 | Media (6.4) | 0.24% | — | 21 dic 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes… |
| CVE-2025-12492 | Media (5.3) | 0.52% | — | 20 dic 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… |
| CVE-2025-14081 | Media (4.3) | 0.32% | — | 17 dic 2025 | The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in… |
| CVE-2025-13217 | Media (6.4) | 0.29% | — | 17 dic 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all… |
| CVE-2025-47691 | Media (5.5) | 0.25% | — | 7 may 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3. |
| CVE-2025-1702 | Alta (7.5) | 0.72% | — | 5 mar 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all… |
| CVE-2024-12276 | Media (6.5) | 0.36% | — | 21 feb 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to,… |
| CVE-2025-0318 | Media (5.3) | 0.36% | — | 18 ene 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1… |
| CVE-2025-0308 | Alta (7.5) | 0.53% | — | 18 ene 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions… |
| CVE-2024-10528 | Media (4.3) | 0.58% | — | 21 nov 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability… |
| CVE-2024-8520 | Media (4.3) | 0.34% | — | 4 oct 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… |
| CVE-2024-8519 | Media (5.4) | 0.44% | — | 4 oct 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin'… |
| CVE-2024-2765 | Media (5.4) | 0.50% | — | 2 may 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL… |
| CVE-2024-1071 | Crítica (9.8) | 89% | — | 13 mar 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to… |
| CVE-2024-2123 | Media (6.1) | 27% | — | 13 mar 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all… |
| CVE-2023-31216 | Alta (8.8) | 0.27% | — | 17 jul 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions. |
| CVE-2023-3460 | Crítica (9.8) | 72% | — | 4 jul 2023 | The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.