CVE-2015-9402: Usersultra Users Ultra Membership

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.

Affected products

  • Usersultra Users Ultra Membership: before 1.5.59 (fixed in 1.5.59)

Published 2019-09-20. Last modified 2026-06-17.