Known Vulnerabilities for Ultimate-member by Ultimate Member
Listed below are 7 of the newest known vulnerabilities associated with "Ultimate-member" by "Ultimate Member".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-15290 json | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin f... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-14245 json | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass lead... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-12251 json | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes ... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-11766 json | The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profil... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-8489 json | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin f... | Not Provided | 2026-07-03 | 2026-07-06 |
| CVE-2026-7761 json | The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2020-37169 json | WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to i... | Not Provided | 2026-05-13 | 2026-05-13 |