CVE-2018-0590: Ultimatemember User Profile & Membership

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.

Affected products

  • Ultimatemember User Profile & Membership: before 2.0.4 (fixed in 2.0.4)

Published 2018-05-14. Last modified 2026-06-17.