Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ultimate Member MEDIUM 6.5
CVE-2024-12276

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.10.0+
Fix from $1,600 2025-02-21
Ultimate Member MEDIUM 5.3
CVE-2025-0318

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.9.2+
Fix from $1,600 2025-01-18
Ultimate Member HIGH 7.5
CVE-2025-0308

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.9.2+
Fix from $1,950 2025-01-18
Forumwp CRITICAL 9.8
CVE-2024-54367

Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a throu…

Fix: 2.1.1+
Fix from $2,300 2024-12-16
Jobboardwp HIGH 8.8
CVE-2023-23715

Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Con…

Fix: after 1.2.2
Fix from $1,950 2024-12-09
Forumwp MEDIUM 6.1
CVE-2024-10879

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_…

Fix: 2.1.3+
Fix from $1,600 2024-12-06
Forumwp MEDIUM 6.1
CVE-2024-11204

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions u…

Fix: 2.1.3+
Fix from $1,600 2024-12-06
Jobboardwp MEDIUM 6.1
CVE-2024-10880

The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_…

Fix: 1.3.1+
Fix from $1,600 2024-11-23
Ultimate Member MEDIUM 5.4
CVE-2024-8519

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.8.7+
Fix from $1,600 2024-10-04
Forumwp HIGH 8.8
CVE-2024-8428

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all …

Fix: after 2.0.2
Fix from $1,950 2024-09-06
Ultimate Member MEDIUM 5.4
CVE-2024-2765

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.8.5+
Fix from $1,600 2024-05-02
Ultimate Member CRITICAL 9.8
CVE-2024-1071EPSS 89%

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.8.3+
Fix from $2,300 2024-03-13
Ultimate Member MEDIUM 6.1
CVE-2024-2123EPSS 27%

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.8.4+
Fix from $1,600 2024-03-13
Ultimate Member HIGH 8.8
CVE-2023-31216

Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.

Fix: after 2.6.0
Fix from $1,950 2023-07-17
Ultimate Member CRITICAL 9.8
CVE-2023-3460EPSS 72%

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allo…

Fix: 2.6.7+
Fix from $2,300 2023-07-04
Jobboardwp HIGH 7.5
CVE-2022-4061

The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthentic…

Fix: 1.2.2+
Fix from $1,950 2022-12-19
Ultimate Member HIGH 7.2
CVE-2022-3384

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_opt…

Fix: after 2.5.0
Fix from $1,950 2022-11-29
Ultimate Member HIGH 7.2
CVE-2022-3383

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from…

Fix: after 2.5.0
Fix from $1,950 2022-11-29
Ultimate Member HIGH 7.5
CVE-2022-3966

A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_templat…

Fix: 2.5.1+
Fix from $1,950 2022-11-13
Ultimate Member MEDIUM 5.4
CVE-2022-1208

The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pag…

Fix: after 2.3.2
Fix from $1,600 2022-06-13
Ultimate Member MEDIUM 5.4
CVE-2022-1209

The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of…

Fix: after 2.3.1
Fix from $1,600 2022-05-10
Ultimate Member MEDIUM 5.4
CVE-2021-24306

The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate o…

Fix: 2.1.20+
Fix from $1,600 2021-05-24
Ultimate Member MEDIUM 5.3
CVE-2020-36170

The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.

Fix: 2.1.13+
Fix from $1,600 2021-01-06
Ultimate Member CRITICAL 9.8
CVE-2020-36155EPSS 9%

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacke…

Fix: 2.1.12+
Fix from $2,300 2021-01-04
Ultimate Member CRITICAL 9.8
CVE-2020-36157

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to th…

Fix: 2.1.12+
Fix from $2,300 2021-01-04
Ultimate Member HIGH 8.8
CVE-2020-36156

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any use…

Fix: 2.1.12+
Fix from $1,950 2021-01-04
Ultimate Member MEDIUM 5.3
CVE-2020-6859

Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress …

Fix: after 2.1.2
Fix from $1,600 2020-01-13
Ultimate Member MEDIUM 5.4
CVE-2019-14945

The ultimate-member plugin before 2.0.54 for WordPress has XSS.

Fix: 2.0.54+
Fix from $1,600 2019-08-12
Ultimate Member MEDIUM 5.4
CVE-2019-14946

The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.

Fix: 2.0.52+
Fix from $1,600 2019-08-12
Ultimate Member MEDIUM 5.4
CVE-2019-14947

The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.

Fix: 2.0.52+
Fix from $1,600 2019-08-12