Cross-Site Scripting
29 records39.7%First: 2015. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 73 vulnerability records associated with Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, published between 2015 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2015 | 4 | |
| 2016 | 3 | |
| 2017 | 1 | |
| 2018 | 13 | |
| 2019 | 13 | |
| 2020 | 6 | |
| 2021 | 1 | |
| 2022 | 8 | |
| 2023 | 3 | |
| 2024 | 6 | |
| 2025 | 10 | |
| 2026 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 10 | 13.7% |
| High | 15 | 20.5% |
| Medium | 48 | 65.8% |
First: 2015. Latest: 2026.
First: 2015. Latest: 2026.
First: 2018. Latest: 2023.
First: 2016. Latest: 2025.
First: 2018. Latest: 2024.
First: 2018. Latest: 2022.
First: 2024. Latest: 2025.
First: 2022. Latest: 2025.
First: 2018. Latest: 2018.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.12.02.11.22.11.32.11.12.10.42.10.22.10.12.10.02.9.22.9.02.8.72.8.52.8.42.8.32.6.92.6.72.6.12.5.12.4.12.4.22.3.22.4.02.1.202.1.132.1.122.1.72.1.32.0.42.0.542.0.522.0.402.0.462.0.332.0.282.0.222.0.182.0.72.0.111.3.841.3.761.3.651.3.401.3.291.3.181.3.01.0.84Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.11.4 | Ultimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field | July 2, 2026 | 2.12.0 | Medium |
*-2.11.4 | Ultimate Member <= 2.11.4 - Authenticated (Contributor+) Account Takeover via Password Reset Link Disclosure | June 23, 2026 | 2.12.0 | High |
*-2.11.1 | Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets | April 3, 2026 | 2.11.2 | Medium |
*-2.11.2 | Ultimate Member <= 2.11.2 - Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag | March 27, 2026 | 2.11.3 | High |
*-2.11.1 | Ultimate Member <= 2.11.1 - Reflected Cross-Site Scripting via Filter Parameters | February 17, 2026 | 2.11.2 | Medium |
*-2.11.0 | Ultimate Member <= 2.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | December 20, 2025 | 2.11.1 | Medium |
*-2.11.0 | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 - Unauthenticated Sensitive Information Exposure | December 19, 2025 | 2.11.1 | Medium |
*-2.11.0 | Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Profile Privacy Setting Bypass | December 16, 2025 | 2.11.1 | Medium |
*-2.11.0 | Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value' | December 16, 2025 | 2.11.1 | Medium |
*-2.10.3 | Ultimate Member <= 2.10.3 - Authenticated (Administrator+) Arbitrary Function Call | May 7, 2025 | 2.10.4 | High |
*-2.10.1 | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection | April 16, 2025 | 2.10.2 | High |
*-2.10.0 | Ultimate Member <= 2.10.0 - Unauthenticated SQL Injection via search Parameter | March 4, 2025 | 2.10.1 | High |
*-2.9.2 | Ultimate Member <= 2.9.2 - Authenticated SQL Injection | February 20, 2025 | 2.10.0 | Medium |
*-2.9.1 | Ultimate Member <= 2.9.1 - Unauthenticated SQL Injection | January 17, 2025 | 2.9.2 | High |
*-2.9.1 | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure | January 17, 2025 | 2.9.2 | Medium |
*-2.8.9 | Ultimate Member <= 2.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture Update | November 20, 2024 | 2.9.0 | Medium |
*-2.8.6 | Ultimate Member <= 2.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting | October 3, 2024 | 2.8.7 | Medium |
*-2.8.6 | Ultimate Member <= 2.8.6 - Cross-Site Request Forgery to Membership Status Change | October 3, 2024 | 2.8.7 | Medium |
*-2.8.4 | Ultimate Member <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting | April 10, 2024 | 2.8.5 | Medium |
*-2.8.3 | Ultimate Member <= 2.8.3 - Unauthenticated Stored Cross-Site Scripting | March 8, 2024 | 2.8.4 | High |
2.1.3-2.8.2 | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.1.3 - 2.8.2 - Unauthenticated SQL Injection | February 23, 2024 | 2.8.3 | Critical |
*-2.6.8 | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.6.8 - Cross-Site Request Forgery | August 8, 2023 | 2.6.9 | Medium |
*-2.6.6 | Ultimate Member <= 2.6.6 - Privilege Escalation via Arbitrary User Meta Updates | June 29, 2023 | 2.6.7 | Critical |
*-2.6.0 | Ultimate Member <= 2.6.0 - Cross-Site Request Forgery to Form Duplication | May 30, 2023 | 2.6.1 | Medium |
*-2.5.0 | Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Remote Code Execution via Multi-Select | October 28, 2022 | 2.5.1 | High |
Selected source records
Published: July 2, 2026
Published: June 23, 2026
Published: April 3, 2026
Published: March 27, 2026
Published: February 17, 2026
Published: December 20, 2025
Published: December 19, 2025
Published: December 16, 2025
Published: November 9, 2020
Published: November 9, 2020
Published: November 9, 2020
Published: February 23, 2024
Published: March 10, 2015
Published: June 29, 2023
Published: December 6, 2016
Published: April 17, 2017
Ultimate Member’s history is especially relevant to websites that depend on public registration, profile editing and role-based access. The synchronized dataset contains 73 records from March 2015 through July 2026, including 10 critical and 15 high-severity records. Cross-site scripting accounts for 29 records (39.7%), while missing authorization, privilege escalation and other access-related categories form a second important cluster.
The pattern matters because this plugin operates close to identity and account workflows. Recent records include stored cross-site scripting through custom profile fields and a high-severity password-reset-link disclosure record affecting versions through 2.11.4. Historical record count is not a quality score, but repeated findings around profiles, permissions and account recovery justify careful version control and role testing on membership sites.
All 73 associated records are currently marked patched in the synchronized source. That does not mean every installed version is safe; it means a patched state is recorded for each imported vulnerability.
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.