Ultimate Member Widgets for Elementor – WordPress User Directory Security & Risk Analysis

wordpress.org/plugins/ultimate-member-widgets-for-elementor

Build a Searchable Member Directory (with Elementor) ✨

400 active installs v2.4 PHP 8.0+ WP 6.0+ Updated Nov 17, 2025
elementormemberultimate-memberuser-directoryuser-profile
98
A · Safe
CVEs total2
Unpatched0
Last CVENov 27, 2025
Safety Verdict

Is Ultimate Member Widgets for Elementor – WordPress User Directory Safe to Use in 2026?

Generally Safe

Score 98/100

Ultimate Member Widgets for Elementor – WordPress User Directory has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Nov 27, 2025Updated 4mo ago
Risk Assessment

The static analysis of 'ultimate-member-widgets-for-elementor' v2.4 indicates a generally strong security posture with a good adherence to secure coding practices. The plugin demonstrates a high percentage of properly escaped output, a low number of SQL queries executed without prepared statements, and no file operations or external HTTP requests, all of which are positive indicators. Furthermore, the absence of any critical or high severity taint flows is commendable.

However, the vulnerability history reveals two past medium severity vulnerabilities, specifically 'Exposure of Sensitive Information to an Unauthorized Actor' and 'Missing Authorization'. While currently unpatched, this historical pattern suggests a recurring potential for authorization bypasses or information disclosure. The presence of nonce checks and capability checks, while present, could be more robust given the past issues. The limited attack surface of only 5 AJAX handlers, all of which appear to have authentication checks according to the static analysis, is a positive point, but the historical context warrants caution.

In conclusion, the plugin exhibits good secure coding practices in its current version. The main concern stems from its vulnerability history, highlighting a pattern of medium severity issues related to authorization and information exposure. While the current code analysis doesn't reveal immediate critical flaws, the historical context necessitates vigilance and suggests that even with the implemented checks, there might be subtle ways to bypass them or specific scenarios that were exploited in the past.

Key Concerns

  • Past medium severity vulnerabilities
  • Past 'Missing Authorization' vulnerabilities
  • Past 'Exposure of Sensitive Information' vulnerabilities
Vulnerabilities
2

Ultimate Member Widgets for Elementor – WordPress User Directory Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-66116medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Ultimate Member Widgets for Elementor <= 2.3 - Unauthenticated Information Exposure

Nov 27, 2025 Patched in 2.4 (24d)
CVE-2025-12778medium · 5.3Missing Authorization

Ultimate Member Widgets for Elementor <= 2.3 - Missing Authorization to Unauthenticated Information Exposure

Nov 19, 2025 Patched in 2.4 (1d)
Code Analysis
Analyzed Mar 16, 2026

Ultimate Member Widgets for Elementor – WordPress User Directory Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
7 prepared
Unescaped Output
17
358 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

78% prepared9 total queries

Output Escaping

95% escaped375 total outputs
Attack Surface

Ultimate Member Widgets for Elementor – WordPress User Directory Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_dismiss_my_noticeinc\elementor-um-essential.php:620
authwp_ajax_um_filter_usersinc\um-user-list-ajax-handlers.php:390
noprivwp_ajax_um_filter_usersinc\um-user-list-ajax-handlers.php:391
authwp_ajax_wp_filter_usersinc\wp-user-list-ajax-handlers.php:32
noprivwp_ajax_wp_filter_usersinc\wp-user-list-ajax-handlers.php:33
WordPress Hooks 13
actionadmin_noticesinc\elementor-um-essential.php:18
actionelementor/elements/categories_registeredinc\elementor-um-essential.php:494
actionwp_enqueue_scriptsinc\elementor-um-essential.php:618
actionadmin_noticesinc\elementor-um-essential.php:621
actionadmin_enqueue_scriptsinc\elementor-um-essential.php:622
actioninitum-addon-elementor.php:49
actionplugins_loadedum-addon-elementor.php:51
actionadmin_noticesum-addon-elementor.php:61
actionadmin_noticesum-addon-elementor.php:66
actionelementor/initum-addon-elementor.php:70
actionwp_enqueue_scriptsum-addon-elementor.php:71
actionelementor/editor/after_enqueue_scriptsum-addon-elementor.php:72
actionelementor/widgets/widgets_registeredum-addon-elementor.php:73
Maintenance & Trust

Ultimate Member Widgets for Elementor – WordPress User Directory Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 17, 2025
PHP min version8.0
Downloads11K

Community Trust

Rating100/100
Number of ratings2
Active installs400
Developer Profile

Ultimate Member Widgets for Elementor – WordPress User Directory Developer Profile

UserElements

6 plugins · 680 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
13 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Member Widgets for Elementor – WordPress User Directory

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-member-widgets-for-elementor/assets/css/um-elementor.css/wp-content/plugins/ultimate-member-widgets-for-elementor/assets/js/um-elementor.js
Script Paths
/wp-content/plugins/ultimate-member-widgets-for-elementor/assets/js/um-elementor.js
Version Parameters
ultimate-member-widgets-for-elementor/assets/css/um-elementor.css?ver=ultimate-member-widgets-for-elementor/assets/js/um-elementor.js?ver=

HTML / DOM Fingerprints

CSS Classes
elementor-um-addons-elementor
FAQ

Frequently Asked Questions about Ultimate Member Widgets for Elementor – WordPress User Directory