Pricing
Case studies
Login
Start trial
Ultimate Member
Ultimate Member
Developer
2.11.3
Latest version
200,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
42 patched
15 Mitigation rules
Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag vulnerability
<= 2.11.2
1 day ago
Reflected Cross-Site Scripting via Filter Parameters vulnerability
<= 2.11.1
20/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes vulnerability
<= 2.11.0
31/12/2025
Unauthenticated Sensitive Information Exposure vulnerability
<= 2.11.0
19/12/2025
Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value' vulnerability
<= 2.11.0
18/12/2025
Authenticated (Subscriber+) Profile Privacy Setting Bypass vulnerability
<= 2.11.0
17/12/2025
Arbitrary Function Call vulnerability
<= 2.10.3
07/05/2025
Unauthenticated Blind SQL Injection vulnerability
<= 2.10.1
17/04/2025
Unauthenticated SQL Injection via search Parameter vulnerability
<= 2.10.0
04/03/2025
Authenticated SQL Injection vulnerability
<= 2.9.2
20/02/2025
Information Exposure vulnerability
<= 2.9.1
17/01/2025
Unauthenticated SQL Injection vulnerability
<= 2.9.1
17/01/2025
Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture Update vulnerability
<= 2.8.9
21/11/2024
Cross-Site Request Forgery to Membership Status Change vulnerability
<= 2.8.6
04/10/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.8.6
04/10/2024
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
<= 2.8.4
15/04/2024
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 2.8.3
08/03/2024
Unauthenticated SQL Injection vulnerability
2.1.3-2.8.2
23/02/2024
Cross-Site Request Forgery vulnerability
<= 2.6.8
09/08/2023
Unauthenticated Privilege Escalation
<= 2.6.6
29/06/2023
Cross Site Request Forgery (CSRF) vulnerability
<= 2.6.0
22/06/2023
Auth. Directory Traversal vulnerability
<= 2.5.0
28/10/2022
Auth. Directory Traversal vulnerability
<= 2.5.0
28/10/2022
Auth. Remote Code Execution vulnerability
<= 2.5.0
28/10/2022
Auth. Limited Remote Code Execution vulnerability
<= 2.5.0
28/10/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 2.3.2
02/06/2022
Open Redirect vulnerability
<= 2.3.1
01/05/2022
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.1.19
07/05/2021
Unauthenticated/Authenticated Privilege Escalation
<= 2.1.11
09/11/2020
Insecure Direct Object Reference (IDOR) vulnerability
<= 2.1.2
22/01/2020
Cross-Site Scripting (XSS) vulnerability
<= 2.0.53
14/08/2019
Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) vulnerabilities
<= 2.0.51
13/07/2019
Multiple vulnerabilities
<= 2.0.45
16/05/2019
Cross-Site Request Forgery (CSRF) vulnerability
<= 2.0.39
04/04/2019
Cross-Site Request Forgery (CSRF) vulnerability
<= 2.0.32
27/11/2018
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 2.0.21
28/08/2018
Unauthenticated Arbitrary File Upload vulnerability
<= 2.0.21
09/08/2018
Unauthenticated Change Passwords
<= 1.3.75
06/12/2016
Local File Inclusion
<= 1.3.64
10/07/2016
Reflected Cross Site Scripting
<= 1.3.28
02/12/2015
Cross Site Scripting
<= 1.2.994
18/06/2015
Multiple Vulnerabilities
<= 1.0.78
16/03/2015