Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
by Ultimate Member · Membership
Also makes 2 other plugins · 201.8K+ installs across the portfolio →
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
93 health vs 69 average across 180 Membership plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
44.4K
now · peak 611.6K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
8
releases in the last 12 months
2mo ago
latest release · v2.12.1
311
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “200K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-10 · 1,498 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ laquituck5mo ago
It’s very limiting; its templates are basic, you can’t control the images that users upload, and they have very low resolution, which makes it unprofessional. This topic was modified 3 months, 2 weeks ago by laquituck.
Read on wp.org ↗ - ★★★★★ Melody Chaney5mo ago
This plugin never works right. It’s just one screw-up after another that I keep running into. And the support is never able to help (for free). I spend more time trying to fix this plugin than I spend working on anything else on my website. I was having a problem where my user profiles were showing the wrong profile pic. So the user profile pics were showing other people’s profile pics from other profile forms. When I asked support to help me figure out the problem, they offered to solve it for me for $100! Imagine that! They wanted to charge me $100 to fix THEIR SCREWUP! I asked them to just offer suggestions for free on how I can fix it myself. A couple of support associates refused, but I finally talked to one who did offer suggestions, although they didn’t work. I spent 3 whole days working on this until I finally figured it out myself! Now I’ve run into another problem. When I post a shortcode for a form onto a page, it pulls up the wrong form!
Read on wp.org ↗ - ★★★★★ esther07087mo ago
I have been reaching out to support and they do not reply or fix the issues. It is disappointing. I will be moving plugins This topic was modified 5 months, 3 weeks ago by esther0708.
Read on wp.org ↗ - ★★★★★ barjinder9mo ago
This is a very good plugin, it helped me to implement restricted content feature on a website easily.
Read on wp.org ↗ - ★★★★★ difko12mo ago
Seguramente, el mejor plugin para gestionar usuarios, permisos, bloqueos, etc.
Read on wp.org ↗ - ★★★★★ maxellinger1.1y ago
I never leave reviews for plugins, but having just spent several months with Ultimate Member I feel compelled to. I was responsible for migrating a 1,000+ member organization site from an old BuddyPress setup to UM and the transition was lovely. The Stripe integration is particularly well-implemented. Some of the frontend styles and markup are a little outdated, and I would appreciate some easier styling through CSS vars, but my complaints are minimal. All the extensions and sister plugins do what they say on the tin (though the Jobs one needs maybe a little English pass).
Read on wp.org ↗ - ★★★★★ dterry1.2y ago
I’m using this plugin to enhance user profile photo display and it works like a charm. Love how clean and responsive the widget is. It even respects user permissions properly exactly what I needed for a members-only area on my site. Bonus points for not breaking my layout even with heavy CSS customization.
Read on wp.org ↗ - ★★★★★ Phil1.4y ago
Super plugin and easy to use.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2026-08-24 Version 2.13.0 Enhancements Added: Using illegal_user_logins filter to sanitize the user_login field value during registration or upgrade. Added: Using wp-cli/wp-config-transformer library to set Ultimate Member > API keys settings con 2.13.0
- 2026-07-06 Version 2.12.1 Enhancements Added: Ability to handle local website URLs resources (image, audio, video from Media Library, 3rd-party local URLs embed to iframe) in the oEmbed-type field value. Added: The API key field type for the sett 2.12.1
- 2026-06-12 Version 2.12.0 Bugfixes Fixed: Security issue, CVE ID: CVE-2026-7761. ** Restricted get_directory_by_hash() function to only match posts with post_type=’um_directory’ and publish post status. ** Used 0 === strpos() instead of strstr() 2.12.0
Known vulnerabilities
via Wordfence Intelligence75 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-24 CVE-2026-18547 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.12.1 Patched in 2.13.0
- 2026-07-02 CVE-2026-8489 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.4 Patched in 2.12.0
- Medium · 6.4 Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets ↗2026-04-03 CVE-2025-15064 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.1 Patched in 2.11.2
- 2026-02-17 CVE-2026-1404 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.1 Patched in 2.11.2
- Medium · 6.4 Ultimate Member <= 2.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ↗2025-12-20 CVE-2025-13220 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.0 Patched in 2.11.1
- 2025-12-19 CVE-2025-12492 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.11.0 Patched in 2.11.1
- Medium · 6.4 Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value' ↗2025-12-16 CVE-2025-13217 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.0 Patched in 2.11.1
- 2025-05-07 CVE-2025-47691 Improper Control of Generation of Code ('Code Injection') Affects <= 2.10.3 Patched in 2.10.4
- 2025-04-16 CVE-2026-15290 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.10.1 Patched in 2.10.2
- 2025-03-04 CVE-2025-1702 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.10.0 Patched in 2.10.1
- 2025-02-20 CVE-2024-12276 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.9.2 Patched in 2.10.0
- 2025-01-17 CVE-2025-0318 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.9.1 Patched in 2.9.2
- 2025-01-17 CVE-2025-0308 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.9.1 Patched in 2.9.2
- 2024-10-03 CVE-2024-8519 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.6 Patched in 2.8.7
- 2024-04-10 CVE-2024-2765 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.4 Patched in 2.8.5
- 2024-03-08 CVE-2024-2123 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.3 Patched in 2.8.4
- 2024-02-23 CVE-2024-1071 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects 2.1.3 - 2.8.2 Patched in 2.8.3
- 2023-08-08 Cross-Site Request Forgery (CSRF) Affects <= 2.6.8 Patched in 2.6.9
- 2022-10-28 CVE-2022-2445 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects 1.0 - 2.5.0 Patched in 2.5.1
- 2022-10-28 CVE-2022-3361 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.5.0 Patched in 2.5.1
- 2022-10-28 CVE-2022-3384 Improper Control of Generation of Code ('Code Injection') Affects <= 2.5.0 Patched in 2.5.1
- 2022-10-28 CVE-2022-3383 Improper Control of Generation of Code ('Code Injection') Affects <= 2.5.0 Patched in 2.5.1
- 2022-07-15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 2.4.0 Patched in 2.4.1
- 2022-07-14 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.4.1 Patched in 2.4.2
- Medium · 4.3 Ultimate Member <= 2.3.1 - Arbitrary Redirect ↗2022-04-29 CVE-2022-1209 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 2.3.1 Patched in 2.3.2
- 2022-03-21 CVE-2022-1208 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.3.2 Patched in 2.4.0
- 2021-05-07 CVE-2021-24306 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.1.20 Patched in 2.1.20
- Medium · 6.5 Ultimate Member <= 2.1.12 - Cross-Site Scripting ↗2020-12-09 CVE-2020-36170 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.1.13 Patched in 2.1.13
- Medium · 6.1 Ultimate Member <= 2.1.6 - Open Redirect ↗2020-07-23 URL Redirection to Untrusted Site ('Open Redirect') Affects < 2.1.7 Patched in 2.1.7
- Medium · 6.1 Ultimate Member <= 1.3.88 - Cross Site Scripting ↗2019-08-12 CVE-2018-0585 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.3.88 Patched in 2.0.4
- Medium · 4.3 Ultimate Member <= 2.0.3 - Directory Traversal ↗2019-08-12 CVE-2018-0586 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 2.0.4 Patched in 2.0.4
- Medium · 6.1 Ultimate Member <= 2.0.3 - Cross Site Scripting ↗2019-08-12 CVE-2018-20965 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.3 Patched in 2.0.4
- Medium · 6.4 Ultimate Member <= 2.0.53 - Cross-Site Scripting ↗2019-07-22 CVE-2019-14945 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.53 Patched in 2.0.54
- Medium · 5.4 Ultimate Member <= 2.0.51 - Cross-Site Request Forgery and Stored Cross-Site Scripting ↗2019-06-24 CVE-2019-14947 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.51 Patched in 2.0.52
- Medium · 6.1 Ultimate Member <= 2.0.51 - Cross-Site Request Forgery and Stored Cross-Site Scripting ↗2019-06-24 CVE-2019-14946 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.51 Patched in 2.0.52
- 2019-05-13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.0.46 Patched in 2.0.46
- Critical · 9.4 Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.0.45 - Arbitrary File Deletion/Read ↗2019-05-13 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.0.45 Patched in 2.0.46
- 2019-05-13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.45 Patched in 2.0.46
- 2018-11-27 Cross-Site Request Forgery (CSRF) Affects <= 2.0.32 Patched in 2.0.33
- 2018-10-06 CVE-2018-17866 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.27 Patched in 2.0.28
- Medium · 6.1 Ultimate Member <= 2.0.21 - Cross-Site Scripting ↗2018-08-09 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.0.22 Patched in 2.0.22
- 2018-08-08 Unrestricted Upload of File with Dangerous Type Affects < 2.0.22 Patched in 2.0.22
- 2018-07-03 CVE-2018-13136 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.17 Patched in 2.0.18
- Medium · 4.3 Ultimate Member <= 2.0.3 - Improper Access Control ↗
- 2018-05-10 CVE-2018-0590 Authorization Bypass Through User-Controlled Key Affects < 2.0.4 Patched in 2.0.4
- Medium · 4.3 Ultimate Member <= 2.0.39 - Directory Traversal ↗2018-05-10 CVE-2018-0588 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.0.39 Patched in 2.0.40
- 2018-05-10 CVE-2018-0587 Unrestricted Upload of File with Dangerous Type Affects < 2.0.4 Patched in 2.0.4
- 2018-04-23 CVE-2018-10234 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.0.11 Patched in 2.0.11
- Medium · 6.1 Ultimate Member <= 2.0.3 - Cross-Site Scripting ↗2018-02-14 CVE-2018-6943 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.0.4 Patched in 2.0.4
- Medium · 6.1 Ultimate Member <= 2.0 - Cross-Site Scripting ↗2018-02-14 CVE-2018-6944 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0 Patched in 2.0.4
- Critical · 9.8 Ultimate Member <= 1.3.83 - Shortcode Injection ↗2017-04-17 Missing Authorization Affects <= 1.3.83 Patched in 1.3.84
- 2016-12-06 Missing Authorization Affects <= 1.3.75 Patched in 1.3.76
- Critical · 9.1 Ultimate Member <= 1.3.64 - Local File Inclusion ↗2016-07-10 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects < 1.3.65 Patched in 1.3.65
- Medium · 6.1 Ultimate Member <= 1.3.39 - Cross-Site Scripting ↗2016-04-06 CVE-2016-10872 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.3.40 Patched in 1.3.40
- 2015-12-02 CVE-2015-8354 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.3.29 Patched in 1.3.29
- Medium · 6.1 Ultimate Member <= 1.3.17 - Cross-Site Scripting ↗2015-08-20 CVE-2015-9304 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.3.17 Patched in 1.3.18
- 2015-06-18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 1.2.98 - 1.2.997 Patched in 1.3.0
- 2015-03-10 Missing Authorization Affects < 1.0.84 Patched in 1.0.84
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 49 languages, 10 at 90% or more
Plus 25 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
- U Ultimate Member – reCAPTCHA 20K+ installs · 3.8★ · 4 shared tags C
-
WP User Manager – User Profile Builder & Membership 10K+ installs · 4.7★ · 4 shared tags A -
Ultimate Member – Terms & Conditions 4K+ installs · 4.0★ · 4 shared tags C -
Ultimate Member – Online Users 3K+ installs · 3.9★ · 4 shared tags C -
Membership For WooCommerce 900+ installs · 4.3★ · 4 shared tags A -
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 100K+ installs · 3.1★ · 3 shared tags B
Embed this report card
Drop a live Pulse card for Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/ultimate-member" width="480" height="300" style="border:0" loading="lazy" title="Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin — Plugin Pulse"></iframe> Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: 200K+ active installs, 4.4★ (1,444 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/ultimate-member