WordPress Ultimate Member Plugin

Ultimate Member is the 1 user profile membership plugin for WordPress. The plugin makes it a breeze for users to sign-up and become members of your website.

Severity Summary:

Critical: 4 High: 8 Medium: 25
Reference
Title
Severity
WordPress Ultimate Member Plugin Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Critical
Unauthorized Admin Access for Ultimate Member plugin
Critical
WordPress Ultimate Member Plugin Vulnerability
Critical
WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability
Critical
WordPress Ultimate Member Plugin Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
High
WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability
High
WordPress Ultimate Member Plugin Other Vulnerability
High
WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability
High
WordPress Ultimate Member Plugin Weak Password Recovery Mechanism for Forgotten Password Vulnerability
High
WordPress Ultimate Member Plugin Other Vulnerability
High
WordPress Ultimate Member Plugin Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability
High
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
WordPress Ultimate Member Plugin Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Missing Authorization Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Authorization Bypass Through User-Controlled Key Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
WordPress Ultimate Member Plugin Vulnerability
Medium
WordPress Ultimate Member Plugin Vulnerability
Medium
WordPress Ultimate Member Plugin URL Redirection to Untrusted Site (Open Redirect) Vulnerability
Medium