
Login Widget for Ultimate Member Security & Risk Analysis
wordpress.org/plugins/login-widget-for-ultimate-memberEasily add a login widget that works with Ultimate Member
Is Login Widget for Ultimate Member Safe to Use in 2026?
Generally Safe
Score 90/100Login Widget for Ultimate Member has a strong security track record. Known vulnerabilities have been patched promptly.
The 'login-widget-for-ultimate-member' plugin version 1.1.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and properly escaping the vast majority of its output. The absence of file operations, external HTTP requests, and bundled libraries further reduces potential attack vectors. However, the presence of one unprotected AJAX handler significantly elevates risk, as it represents an accessible entry point that could be exploited without proper authentication or authorization checks. This is a critical oversight that leaves the plugin vulnerable to unauthorized actions.
The vulnerability history for this plugin is concerning. The single recorded CVE, classified as 'PHP Remote File Inclusion,' is a high-severity vulnerability. While it is currently marked as patched, the nature of this vulnerability suggests that the plugin has, in the past, been susceptible to serious code execution attacks. The fact that a high-severity RFI vulnerability existed at all points to potential weaknesses in how the plugin handles user-supplied input for file operations, even if such operations are not present in the current static analysis. This historical context, combined with the current unprotected AJAX endpoint, suggests a pattern of potential security oversights that require careful monitoring.
In conclusion, while 'login-widget-for-ultimate-member' v1.1.3 has adopted some sound security practices, the unprotected AJAX handler is a major vulnerability that needs immediate attention. The past high-severity RFI vulnerability, even though patched, highlights a potential underlying architectural weakness. Users should proceed with caution and ensure this specific AJAX endpoint is secured or the plugin is updated to a version that addresses this issue.
Key Concerns
- 1 AJAX handler without auth checks
- 1 High severity vulnerability historically
Login Widget for Ultimate Member Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Login Widget for Ultimate Member <= 1.1.2 - Authenticated (Contributor+) Local File Inclusion
Login Widget for Ultimate Member Code Analysis
Output Escaping
Login Widget for Ultimate Member Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Login Widget for Ultimate Member Maintenance & Trust
Maintenance Signals
Community Trust
Login Widget for Ultimate Member Alternatives
Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages
bp-better-messages
Real-time messaging and chat rooms for WordPress ecosystem: private conversations, public and private chat rooms, video & audio calls, and more.
Sidebar Login
sidebar-login
Easily add an ajax-enhanced login widget to your WordPress site sidebar.
Login Widget With Shortcode
login-sidebar-widget
This is a simple login form in the widget. This will allow users to login to the site from frontend.
Toolbox for Asgaros Forum
toolbox-for-asgaros-forum
This toolbox allows you to extend the functionality of Asgaros Forum.
Ultimate Member Custom Tab Builder Lite
um-custom-tab-builder-lite
An easy way to add custom profile tabs to Ultimate Member Profile. Ultimate Member 2.0 compatible
Login Widget for Ultimate Member Developer Profile
17 plugins · 2K total installs
How We Detect Login Widget for Ultimate Member
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-widget-for-ultimate-member/build/index.js/wp-content/plugins/login-widget-for-ultimate-member/build/style-index.css/wp-content/plugins/login-widget-for-ultimate-member/build/index.asset.php/wp-content/plugins/login-widget-for-ultimate-member/build/index.jslogin-widget-for-ultimate-member/build/style-index.css?ver=login-widget-for-ultimate-member/build/index.js?ver=HTML / DOM Fingerprints
um-login-widgetum-login-form-fielddata-um-login-widgetum_login_widget_params/wp-json/um-login-widget/v1/get_member_forms[um_login_widget