CVE-2015-9395: Usersultra Users Ultra Membership

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.

Affected products

  • Usersultra Users Ultra Membership: before 1.5.64 (fixed in 1.5.64)

Published 2019-09-20. Last modified 2026-06-17.