WP User Manager – User Profile Builder & Membership Security & Risk Analysis

wordpress.org/plugins/wp-user-manager

The most customizable profiles & community builder WordPress plugin with front-end login, registration, profile customization and content restriction.

10K active installs v2.9.15 PHP 7.4+ WP 4.9+ Updated Feb 26, 2026
communitymembersmembershipuser-profileuser-registration
89
A · Safe
CVEs total7
Unpatched0
Last CVEDec 11, 2025
Safety Verdict

Is WP User Manager – User Profile Builder & Membership Safe to Use in 2026?

Generally Safe

Score 89/100

WP User Manager – User Profile Builder & Membership has a strong security track record. Known vulnerabilities have been patched promptly.

7 known CVEsLast CVE: Dec 11, 2025Updated 1mo ago
Risk Assessment

The wp-user-manager plugin v2.9.15 exhibits a mixed security posture. While it demonstrates good practices in areas like prepared SQL statements (69%) and output escaping (88%), significant concerns arise from its attack surface and vulnerability history. The presence of 8 unprotected AJAX handlers is a primary risk, as these can be leveraged for unauthorized actions without proper authentication checks. The taint analysis further highlights issues with 4 high-severity flows involving unsanitized paths, indicating potential for path traversal or arbitrary file access vulnerabilities.

The plugin's history of 7 known CVEs, including 2 high-severity ones, with common types like missing authorization and deserialization, suggests a recurring pattern of exploitable weaknesses. The fact that the last vulnerability was recorded in December 2025 (though this may be a future date and should be verified) implies ongoing security challenges. While there are no currently unpatched CVEs, the historical prevalence of critical and high-severity issues, coupled with specific code-level concerns like unprotected AJAX endpoints and high-severity taint flows, warrants caution.

In conclusion, while the plugin shows some strengths in code hygiene, the identified unprotected entry points, critical taint flows, and a history of significant vulnerabilities point to a moderate to high-risk profile. Users should exercise caution and ensure this plugin is thoroughly audited and updated, especially given the identified areas of concern.

Key Concerns

  • Unprotected AJAX handlers present
  • High severity taint flows with unsanitized paths
  • History of High severity vulnerabilities
  • History of Medium severity vulnerabilities
  • Use of dangerous function: unserialize
  • Use of dangerous function: preg_replace(/e)
  • Bundled libraries with potential for outdated versions
Vulnerabilities
7

WP User Manager – User Profile Builder & Membership Security Vulnerabilities

CVEs by Year

2 CVEs in 2021
2021
3 CVEs in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
2
Medium
5

7 total CVEs

CVE-2025-13320medium · 6.8External Control of File Name or Path

WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter

Dec 11, 2025 Patched in 2.9.13 (8d)
CVE-2025-60245high · 7.5Deserialization of Untrusted Data

User Manager <= 2.9.12 - Authenticated (Subscriber+) PHP Object Injection

May 19, 2025 Patched in 2.9.13 (215d)
CVE-2024-10216medium · 4.3Missing Authorization

WP User Manager – User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Carbon Fields Custom Sidebar Addition/Removal

Nov 22, 2024 Patched in 2.9.12 (1d)
CVE-2024-10537medium · 4.3Missing Authorization

WP User Manager – User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Authenticated (Subscriber+) User Meta Key Enumeration

Nov 22, 2024 Patched in 2.9.12 (1d)
CVE-2024-43336medium · 4.3Cross-Site Request Forgery (CSRF)

WP User Manager <= 2.9.10 - Cross-Site Request Forgery

Aug 16, 2024 Patched in 2.9.11 (25d)
CVE-2021-24655high · 7.5Authorization Bypass Through User-Controlled Key

WP User Manager <= 2.6.2 - Arbitrary User Password Reset

Sep 22, 2021 Patched in 2.6.3 (853d)
CVE-2021-24654medium · 5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

User Registration < 2.0.2 - Authenticated Stored Cross-Site Scripting

Sep 6, 2021 Patched in 2.0.2 (869d)
Code Analysis
Analyzed Mar 16, 2026

WP User Manager – User Profile Builder & Membership Code Analysis

Dangerous Functions
3
Raw SQL Queries
26
59 prepared
Unescaped Output
138
1013 escaped
Nonce Checks
39
Capability Checks
55
File Operations
10
External Requests
8
Bundled Libraries
3

Dangerous Functions Found

unserializereturn @unserialize( trim( $data ), array( 'allowed_classes' => false ) ); // phpcs:ignoreincludes\fields\wpum-fields-functions.php:626
preg_replace(/e)preg_replace('/evendor-dist\composer\installers\src\Composer\Installers\MicroweberInstaller.php:89
preg_replace(/e)preg_replace('/evendor-dist\composer\installers\src\Composer\Installers\MicroweberInstaller.php:91

Bundled Libraries

TinyMCEdompdfStripe PHP

SQL Query Safety

69% prepared85 total queries

Output Escaping

88% escaped1151 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

8 flows6 with unsanitized paths
dismiss_notice_ajax (vendor-dist\wp-user-manager\wp-notices\wp-notices.php:166)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

WP User Manager – User Profile Builder & Membership Attack Surface

Entry Points47
Unprotected8

AJAX Handlers 32

authwp_ajax_validate_user_meta_keyincludes\actions.php:1027
authwp_ajax_wpum_send_test_emailincludes\emails\class-wpum-emails-list.php:35
authwp_ajax_wpum_enabled_emailincludes\emails\class-wpum-emails-list.php:36
authwp_ajax_wpum_update_fields_groups_orderincludes\fields\class-wpum-fields-editor.php:48
authwp_ajax_wpum_update_fields_groupincludes\fields\class-wpum-fields-editor.php:49
authwp_ajax_wpum_get_fields_from_groupincludes\fields\class-wpum-fields-editor.php:50
authwp_ajax_wpum_update_fields_orderincludes\fields\class-wpum-fields-editor.php:51
authwp_ajax_wpum_get_field_settingsincludes\fields\class-wpum-fields-editor.php:52
authwp_ajax_wpum_update_fieldincludes\fields\class-wpum-fields-editor.php:53
authwp_ajax_wpum_get_registration_formsincludes\forms\class-wpum-registration-forms-editor.php:41
authwp_ajax_wpum_get_registration_formincludes\forms\class-wpum-registration-forms-editor.php:42
authwp_ajax_wpum_update_registration_formincludes\forms\class-wpum-registration-forms-editor.php:43
authwp_ajax_wpum_save_registration_formincludes\forms\class-wpum-registration-forms-editor.php:44
authwp_ajax_wpum_save_registration_form_settingsincludes\forms\class-wpum-registration-forms-editor.php:45
authwp_ajax_wpum_get_registration_form_fieldincludes\forms\class-wpum-registration-forms-editor.php:46
authwp_ajax_wpum_stripe_manage_billingincludes\integrations\stripe\Account.php:73
authwp_ajax_wpum_stripe_checkoutincludes\integrations\stripe\Account.php:74
authwp_ajax_wpum_stripe_registerincludes\integrations\stripe\Registration.php:76
noprivwp_ajax_wpum_stripe_registerincludes\integrations\stripe\Registration.php:77
authwp_ajax_wpum_stripe_connect_account_infoincludes\integrations\stripe\Settings.php:46
authwp_ajax_wpum_get_rolesincludes\roles\class-wpum-roles-editor.php:44
authwp_ajax_wpum_get_roleincludes\roles\class-wpum-roles-editor.php:45
authwp_ajax_wpum_save_roleincludes\roles\class-wpum-roles-editor.php:46
authwp_ajax_wpum_update_roleincludes\roles\class-wpum-roles-editor.php:47
authwp_ajax_wpum_delete_roleincludes\roles\class-wpum-roles-editor.php:48
authwp_ajax_wpum_create_roleincludes\roles\class-wpum-roles-editor.php:49
authwp_ajax_wpum_shortcodeincludes\shortcodes\class-wpum-shortcode-button.php:40
noprivwp_ajax_wpum_shortcodeincludes\shortcodes\class-wpum-shortcode-button.php:41
authwp_ajax_carbon_fields_add_sidebarvendor-dist\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:24
authwp_ajax_carbon_fields_remove_sidebarvendor-dist\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:25
authwp_ajax_carbon_fields_fetch_association_optionsvendor-dist\htmlburger\carbon-fields\core\Loader\Loader.php:46
authwp_ajax_tdp_dismiss_noticevendor-dist\wp-user-manager\wp-notices\wp-notices.php:73

REST API Routes 1

GET/wp-json/wp-user-manageruser-rolesvendor-dist\wp-user-manager\wpum-blocks\blocks-loader.php:88

Shortcodes 14

[wpum_login_form] includes\shortcodes\shortcodes.php:54
[wpum_password_recovery] includes\shortcodes\shortcodes.php:89
[wpum_login] includes\shortcodes\shortcodes.php:132
[wpum_logout] includes\shortcodes\shortcodes.php:160
[wpum_register] includes\shortcodes\shortcodes.php:230
[wpum_account] includes\shortcodes\shortcodes.php:252
[wpum_profile] includes\shortcodes\shortcodes.php:343
[wpum_restrict_logged_in] includes\shortcodes\shortcodes.php:409
[wpum_restrict_logged_out] includes\shortcodes\shortcodes.php:475
[wpum_restrict_to_users] includes\shortcodes\shortcodes.php:545
[wpum_restrict_to_user_roles] includes\shortcodes\shortcodes.php:616
[wpum_recently_registered] includes\shortcodes\shortcodes.php:653
[wpum_profile_card] includes\shortcodes\shortcodes.php:707
[wpum_user_directory] includes\shortcodes\shortcodes.php:938
WordPress Hooks 334
filterwpum_registered_field_typesincludes\abstracts\class-wpum-field-type.php:141
actioninitincludes\abstracts\class-wpum-field-type.php:144
actionadmin_initincludes\abstracts\class-wpum-shortcode-generator.php:71
actioninitincludes\abstracts\class-wpum-shortcode-generator.php:74
actionswitch_blogincludes\abstracts\class-wpum-wp-db-table.php:259
actionadmin_initincludes\abstracts\class-wpum-wp-db-table.php:260
actionsave_post_pageincludes\actions.php:33
actiondelete_postincludes\actions.php:51
actionadmin_bar_menuincludes\actions.php:104
actionafter_setup_themeincludes\actions.php:140
actioninitincludes\actions.php:179
actionlogin_form_registerincludes\actions.php:196
actionlogin_form_lostpasswordincludes\actions.php:212
actionload-profile.phpincludes\actions.php:228
actiontemplate_redirectincludes\actions.php:256
actionwpum_account_page_contentincludes\actions.php:281
actionuser_profile_update_errorsincludes\actions.php:302
actionpersonal_options_updateincludes\actions.php:306
actionedit_user_profile_updateincludes\actions.php:307
filteruser_row_actionsincludes\actions.php:348
actioninitincludes\actions.php:395
actioninitincludes\actions.php:470
actionafter_wpum_initincludes\actions.php:485
actioncarbon_fields_register_fieldsincludes\actions.php:500
actioncarbon_fields_register_fieldsincludes\actions.php:539
actiontemplate_redirectincludes\actions.php:541
actionprofile_updateincludes\actions.php:600
actionadd_user_to_blogincludes\actions.php:602
actionuser_registerincludes\actions.php:604
actionuser_new_formincludes\actions.php:680
actionshow_user_profileincludes\actions.php:681
actionedit_user_profileincludes\actions.php:682
actiontemplate_redirectincludes\actions.php:698
actionwpum_after_custom_user_updateincludes\actions.php:708
actionwpum_after_user_updateincludes\actions.php:709
actionwpum_after_registration_formincludes\actions.php:738
actionwpum_after_account_formincludes\actions.php:739
actionwpum_after_custom_account_formincludes\actions.php:740
filterwpum_form_skip_field_validationincludes\actions.php:778
filterwpum_conditional_field_validate_rule_value_not_equalsincludes\actions.php:803
filterwpum_conditional_field_validate_rule_value_equalsincludes\actions.php:828
filterwpum_conditional_field_validate_rule_value_containsincludes\actions.php:857
filterwpum_conditional_field_validate_rule_has_valueincludes\actions.php:886
filterwpum_conditional_field_validate_rule_has_no_valueincludes\actions.php:915
filterwpum_conditional_field_validate_rule_value_greaterincludes\actions.php:940
filterwpum_conditional_field_validate_rule_value_lessincludes\actions.php:965
actionwpincludes\actions.php:968
actionthe_contentincludes\actions.php:1030
actionadd_meta_boxesincludes\admin\class-wpum-addon-acf.php:29
actionadmin_noticesincludes\admin\class-wpum-addon-check.php:63
actionadmin_noticesincludes\admin\class-wpum-addon-check.php:99
actionadmin_menuincludes\admin\class-wpum-addons-page.php:42
actionadmin_enqueue_scriptsincludes\admin\class-wpum-addons-page.php:43
filterinstall_plugins_tabsincludes\admin\class-wpum-addons-page.php:44
actioninstall_plugins_wpum_addonsincludes\admin\class-wpum-addons-page.php:45
actionadmin_initincludes\admin\class-wpum-admin-notices.php:24
actionadmin_initincludes\admin\class-wpum-admin-notices.php:25
actioncarbon_fields_register_fieldsincludes\admin\class-wpum-avatars.php:38
filterget_avatar_urlincludes\admin\class-wpum-avatars.php:39
actioncarbon_fields_register_fieldsincludes\admin\class-wpum-avatars.php:43
filterget_avatar_urlincludes\admin\class-wpum-avatars.php:48
filteravatar_defaultsincludes\admin\class-wpum-avatars.php:49
filterpre_option_avatar_defaultincludes\admin\class-wpum-avatars.php:56
filterpre_update_option_wpum_settingsincludes\admin\class-wpum-avatars.php:60
actionadmin_menuincludes\admin\class-wpum-getting-started.php:29
actionadmin_headincludes\admin\class-wpum-getting-started.php:30
actionadmin_initincludes\admin\class-wpum-getting-started.php:31
actioncarbon_fields_register_fieldsincludes\admin\class-wpum-menus.php:32
actionadmin_headincludes\admin\class-wpum-menus.php:33
actionadmin_enqueue_scriptsincludes\admin\class-wpum-menus.php:34
filternav_menu_link_attributesincludes\admin\class-wpum-menus.php:35
filterwp_get_nav_menu_itemsincludes\admin\class-wpum-menus.php:37
actionwp_nav_menu_item_custom_fieldsincludes\admin\class-wpum-menus.php:40
actioninitincludes\admin\class-wpum-options-panel.php:32
filterwpum_menuincludes\admin\class-wpum-options-panel.php:41
filterwpum_settings_tabsincludes\admin\class-wpum-options-panel.php:44
filterwpum_registered_settings_sectionsincludes\admin\class-wpum-options-panel.php:45
filterwpum_registered_settingsincludes\admin\class-wpum-options-panel.php:48
filterwpum_labelsincludes\admin\class-wpum-options-panel.php:58
actionadmin_initincludes\admin\class-wpum-permalinks-settings.php:28
actionadmin_initincludes\admin\class-wpum-permalinks-settings.php:29
actionadmin_initincludes\admin\class-wpum-plugin-updates.php:26
actionadmin_initincludes\admin\class-wpum-plugin-updates.php:27
actionadmin_initincludes\admin\class-wpum-plugin-updates.php:28
actioncarbon_fields_register_fieldsincludes\admin\class-wpum-prevent-password-change.php:28
filtersubmit_wpum_form_validate_fieldsincludes\admin\class-wpum-prevent-password-change.php:29
filtermanage_users_columnsincludes\admin\class-wpum-user-table.php:24
filtermanage_users_custom_columnincludes\admin\class-wpum-user-table.php:25
actionadmin_headincludes\admin\class-wpum-user-table.php:26
actionload-users.phpincludes\admin\class-wpum-user-table.php:27
actionload-users.phpincludes\admin\class-wpum-user-table.php:28
actionload-users.phpincludes\admin\class-wpum-user-table.php:29
actionrestrict_manage_usersincludes\admin\class-wpum-user-table.php:84
actionadmin_enqueue_scriptsincludes\assets.php:40
actionwp_enqueue_scriptsincludes\assets.php:61
actioninitincludes\class-wp-user-manager.php:452
actionplugins_loadedincludes\class-wp-user-manager.php:454
actionafter_setup_themeincludes\compatibility\oceanwp.php:18
actioninitincludes\directories\class-wpum-directories-editor.php:34
actioncarbon_fields_register_fieldsincludes\directories\class-wpum-directories-editor.php:35
actionadmin_footerincludes\directories\class-wpum-directories-editor.php:36
filtermanage_edit-wpum_directory_columnsincludes\directories\class-wpum-directories-editor.php:39
actionmanage_wpum_directory_posts_custom_columnincludes\directories\class-wpum-directories-editor.php:40
filterpost_row_actionsincludes\directories\class-wpum-directories-editor.php:41
filterpost_updated_messagesincludes\directories\class-wpum-directories-editor.php:42
filterbulk_post_updated_messagesincludes\directories\class-wpum-directories-editor.php:43
actioninitincludes\emails\class-wpum-emails-customizer-scripts.php:32
actioncustomize_preview_initincludes\emails\class-wpum-emails-customizer-scripts.php:34
actioncustomize_controls_enqueue_scriptsincludes\emails\class-wpum-emails-customizer-scripts.php:35
actioninitincludes\emails\class-wpum-emails-customizer.php:46
actioncustomize_registerincludes\emails\class-wpum-emails-customizer.php:70
filtercustomize_section_activeincludes\emails\class-wpum-emails-customizer.php:71
filtercustomize_panel_activeincludes\emails\class-wpum-emails-customizer.php:72
actionparse_requestincludes\emails\class-wpum-emails-customizer.php:73
actionadmin_menuincludes\emails\class-wpum-emails-list.php:33
actionadmin_enqueue_scriptsincludes\emails\class-wpum-emails-list.php:34
actionwpum_email_send_beforeincludes\emails\class-wpum-emails.php:106
actionwpum_email_send_afterincludes\emails\class-wpum-emails.php:107
filterwp_mail_fromincludes\emails\class-wpum-emails.php:288
filterwp_mail_from_nameincludes\emails\class-wpum-emails.php:289
filterwp_mail_content_typeincludes\emails\class-wpum-emails.php:290
filterwpum_registered_emailsincludes\emails\wpum-email-functions.php:332
actioninitincludes\fields\class-wpum-field.php:143
actionadmin_menuincludes\fields\class-wpum-fields-editor.php:46
actionadmin_enqueue_scriptsincludes\fields\class-wpum-fields-editor.php:47
actionwpum_field_group_insertincludes\fields\class-wpum-fields-editor.php:55
actionwpum_field_group_deleteincludes\fields\class-wpum-fields-editor.php:56
actionwpum_field_group_deleteincludes\fields\class-wpum-fields-editor.php:57
actionwpum_field_insertincludes\fields\class-wpum-fields-editor.php:58
actionwpum_before_field_deleteincludes\fields\class-wpum-fields-editor.php:59
filterwpum_fields_editor_deregister_modelincludes\fields\types\class-wpum-field-repeater.php:31
filterwpum_register_field_type_settingsincludes\fields\types\class-wpum-field-repeater.php:32
filterwpum_registered_parent_field_typesincludes\fields\types\class-wpum-field-repeater.php:33
filteradmin_footer_textincludes\filters.php:35
filterregister_urlincludes\filters.php:70
filterlostpassword_urlincludes\filters.php:90
filterlogout_urlincludes\filters.php:114
filterlogin_urlincludes\filters.php:137
filterauthenticateincludes\filters.php:183
filterdisplay_post_statesincludes\filters.php:213
filterupload_dirincludes\filters.php:242
filterwpum_registration_form_fieldsincludes\filters.php:266
filterwpum_registration_user_dataincludes\filters.php:303
filterwpum_account_display_fieldincludes\filters.php:305
filterwpum_profile_display_fieldincludes\filters.php:306
filterwpum_field_nameincludes\filters.php:349
filterwpum_field_descriptionincludes\filters.php:350
filterwpum_fields_editor_field_settingsincludes\filters.php:369
actionwp_die_handlerincludes\filters.php:374
filterwpum_user_display_nameincludes\filters.php:392
actionwpincludes\forms\class-wpum-form-login.php:57
actionwpincludes\forms\class-wpum-form-password-recovery.php:59
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-password-recovery.php:61
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-password-recovery.php:62
actionwpincludes\forms\class-wpum-form-password.php:71
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-password.php:72
actionwpincludes\forms\class-wpum-form-privacy.php:72
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-profile.php:74
actionwpincludes\forms\class-wpum-form-profile.php:76
actionwpincludes\forms\class-wpum-form-registration.php:80
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-registration.php:82
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-registration.php:83
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-registration.php:84
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-registration.php:85
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-registration.php:86
filtersubmit_wpum_form_validate_fieldsincludes\forms\class-wpum-form-registration.php:87
actionwpum_registration_form_fieldincludes\forms\class-wpum-form-registration.php:88
actioninitincludes\forms\class-wpum-forms.php:44
actionadmin_menuincludes\forms\class-wpum-registration-forms-editor.php:39
actionadmin_enqueue_scriptsincludes\forms\class-wpum-registration-forms-editor.php:40
filterwpum_form_settings_sanitize_textincludes\forms\class-wpum-registration-forms-editor.php:48
filterwpum_form_settings_sanitize_textareaincludes\forms\class-wpum-registration-forms-editor.php:49
filterwpum_form_settings_sanitize_radioincludes\forms\class-wpum-registration-forms-editor.php:50
filterwpum_form_settings_sanitize_selectincludes\forms\class-wpum-registration-forms-editor.php:51
filterwpum_form_settings_sanitize_checkboxincludes\forms\class-wpum-registration-forms-editor.php:52
filterwpum_form_settings_sanitize_multiselectincludes\forms\class-wpum-registration-forms-editor.php:53
filterwpum_form_settings_sanitize_multicheckboxincludes\forms\class-wpum-registration-forms-editor.php:54
filterwpum_form_settings_sanitize_fileincludes\forms\class-wpum-registration-forms-editor.php:55
actionwpum_registration_form_insertincludes\forms\class-wpum-registration-forms-editor.php:58
actionwpum_before_registration_form_deleteincludes\forms\class-wpum-registration-forms-editor.php:59
actionwpum_registration_form_duplicatedincludes\forms\class-wpum-registration-forms-editor.php:60
actionwp_initialize_siteincludes\install.php:288
actionelementor/elements/categories_registeredincludes\integrations\elementor\class-wpum-elementor-loader.php:39
actionelementor/widgets/registerincludes\integrations\elementor\class-wpum-elementor-loader.php:40
filterelementor/widget/render_contentincludes\integrations\elementor\class-wpum-elementor-loader.php:41
filterwpum_shortcode_logged_in_overrideincludes\integrations\elementor\class-wpum-elementor-loader.php:43
actionelementor/element/after_section_endincludes\integrations\elementor\extensions\class-wpum-restrictioncontrols.php:55
filterwpum_get_account_page_tabsincludes\integrations\stripe\Account.php:69
actionwpum_account_page_content_billingincludes\integrations\stripe\Account.php:70
actiontemplate_redirectincludes\integrations\stripe\Account.php:71
actiontemplate_redirectincludes\integrations\stripe\Account.php:76
actionwpum_account_page_contentincludes\integrations\stripe\Account.php:77
actionwpum_enqueue_frontend_scriptsincludes\integrations\stripe\Assets.php:21
actionadmin_initincludes\integrations\stripe\Connect.php:21
filterwpum_registration_edit_form_settings_sectionsincludes\integrations\stripe\Registration.php:72
filterwpum_get_registration_fieldsincludes\integrations\stripe\Registration.php:73
actionwpum_before_registration_endincludes\integrations\stripe\Registration.php:74
actionwpum_after_existing_registrationincludes\integrations\stripe\Registration.php:75
filterwpum_registered_settings_sectionsincludes\integrations\stripe\Registration.php:78
filterwpum_registered_settingsincludes\integrations\stripe\Settings.php:43
filterwpum_settings_tabsincludes\integrations\stripe\Settings.php:44
actionupdate_option_wpum_settingsincludes\integrations\stripe\Settings.php:45
actionadmin_initincludes\integrations\stripe\Settings.php:47
actionrest_api_initincludes\integrations\stripe\WebhookEndpoint.php:45
actioncortex.routesincludes\permalinks.php:22
actioncortex.routesincludes\permalinks.php:76
actionadmin_menuincludes\roles\class-wpum-roles-editor.php:42
actionadmin_enqueue_scriptsincludes\roles\class-wpum-roles-editor.php:43
actionwp_roles_initincludes\roles\functions.php:10
actionwpum_register_rolesincludes\roles\functions.php:11
actioninitincludes\roles\functions.php:12
actionwpum_register_capsincludes\roles\functions.php:13
filterwpum_get_capabilitiesincludes\roles\functions.php:14
filterwpum_get_capabilitiesincludes\roles\functions.php:15
actioninitincludes\roles\functions.php:17
actionwpum_register_cap_groupsincludes\roles\functions.php:18
filtermce_external_pluginsincludes\shortcodes\class-wpum-shortcode-button.php:34
actionadmin_enqueue_scriptsincludes\shortcodes\class-wpum-shortcode-button.php:35
actionadmin_enqueue_scriptsincludes\shortcodes\class-wpum-shortcode-button.php:36
actionmedia_buttonsincludes\shortcodes\class-wpum-shortcode-button.php:37
filteruser_search_columnsincludes\shortcodes\shortcodes.php:865
actionpre_user_queryincludes\shortcodes\shortcodes.php:874
filterwpum_directory_search_query_argsincludes\shortcodes\shortcodes.php:973
filterwpum_shortcode_logged_in_overrideincludes\shortcodes\shortcodes.php:975
filterwpum_licenses_register_addon_settingsincludes\updates\class-wpum-license.php:134
actioncarbon_fields_theme_options_container_savedincludes\updates\class-wpum-license.php:137
actionadmin_initincludes\updates\class-wpum-license.php:140
actioninitincludes\updates\class-wpum-license.php:143
actionadmin_enqueue_scriptsincludes\updates\class-wpum-updater-settings.php:36
actioncarbon_fields_register_fieldsincludes\updates\class-wpum-updater-settings.php:37
actionadmin_noticesincludes\updates\class-wpum-updater-settings.php:38
actionadmin_footerincludes\updates\class-wpum-updater-settings.php:39
actionadmin_initincludes\updates\free-plugins.php:14
filterpre_set_site_transient_update_pluginsincludes\updates\WPUM_EDD_SL_Plugin_Updater.php:73
filterplugins_apiincludes\updates\WPUM_EDD_SL_Plugin_Updater.php:74
actionadmin_initincludes\updates\WPUM_EDD_SL_Plugin_Updater.php:77
filterpre_set_site_transient_update_pluginsincludes\updates\WPUM_EDD_SL_Plugin_Updater.php:236
actionwidgets_initincludes\widgets.php:27
actioncortex.exit.redirectvendor-dist\brain\cortex\src\Cortex\Controller\RedirectController.php:40
filtertemplate_includevendor-dist\brain\cortex\src\Cortex\Router\ResultHandler.php:108
filterdo_parse_requestvendor-dist\brain\cortex\src\Cortex.php:54
filtercortex.match.donevendor-dist\brain\cortex\src\Cortex.php:105
actioncortex.routesvendor-dist\brain\cortex\src\Routes.php:49
actioncortex.routesvendor-dist\brain\cortex\src\Routes.php:65
actioncortex.groupsvendor-dist\brain\cortex\src\Routes.php:80
actioninitvendor-dist\htmlburger\carbon-fields\core\Container\Block_Container.php:42
filterblock_categories_allvendor-dist\htmlburger\carbon-fields\core\Container\Block_Container.php:94
actionadmin_initvendor-dist\htmlburger\carbon-fields\core\Container\Comment_Meta_Container.php:34
actionedit_commentvendor-dist\htmlburger\carbon-fields\core\Container\Comment_Meta_Container.php:35
filterwp_edit_nav_menu_walkervendor-dist\htmlburger\carbon-fields\core\Container\Nav_Menu_Item_Container.php:38
actionwp_update_nav_menu_itemvendor-dist\htmlburger\carbon-fields\core\Container\Nav_Menu_Item_Container.php:53
actioncarbon_fields_print_nav_menu_item_container_fieldsvendor-dist\htmlburger\carbon-fields\core\Container\Nav_Menu_Item_Container.php:54
actionnetwork_admin_menuvendor-dist\htmlburger\carbon-fields\core\Container\Network_Container.php:39
actionadmin_initvendor-dist\htmlburger\carbon-fields\core\Container\Post_Meta_Container.php:61
actionsave_postvendor-dist\htmlburger\carbon-fields\core\Container\Post_Meta_Container.php:62
actionadd_attachmentvendor-dist\htmlburger\carbon-fields\core\Container\Post_Meta_Container.php:64
actionedit_attachmentvendor-dist\htmlburger\carbon-fields\core\Container\Post_Meta_Container.php:65
actionadmin_initvendor-dist\htmlburger\carbon-fields\core\Container\Term_Meta_Container.php:29
actioninitvendor-dist\htmlburger\carbon-fields\core\Container\Term_Meta_Container.php:30
actionadmin_menuvendor-dist\htmlburger\carbon-fields\core\Container\Theme_Options_Container.php:59
actionadmin_initvendor-dist\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:30
actionprofile_updatevendor-dist\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:31
actionuser_registervendor-dist\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:32
actionshow_user_profilevendor-dist\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:129
actionedit_user_profilevendor-dist\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:130
actionuser_new_formvendor-dist\htmlburger\carbon-fields\core\Container\User_Meta_Container.php:131
actiondelete_termvendor-dist\htmlburger\carbon-fields\core\Datastore\Term_Meta_Datastore.php:24
actionadmin_noticesvendor-dist\htmlburger\carbon-fields\core\Exception\Incorrect_Syntax_Exception.php:18
actionnetwork_admin_noticesvendor-dist\htmlburger\carbon-fields\core\Exception\Incorrect_Syntax_Exception.php:19
filterposts_fields_requestvendor-dist\htmlburger\carbon-fields\core\Field\Association_Field.php:375
filterposts_groupby_requestvendor-dist\htmlburger\carbon-fields\core\Field\Association_Field.php:376
filterposts_orderby_requestvendor-dist\htmlburger\carbon-fields\core\Field\Association_Field.php:377
filterpost_limits_requestvendor-dist\htmlburger\carbon-fields\core\Field\Association_Field.php:378
filterget_terms_fieldsvendor-dist\htmlburger\carbon-fields\core\Field\Association_Field.php:423
filterterms_clausesvendor-dist\htmlburger\carbon-fields\core\Field\Association_Field.php:424
filtercomments_clausesvendor-dist\htmlburger\carbon-fields\core\Field\Association_Field.php:506
actionadmin_print_footer_scriptsvendor-dist\htmlburger\carbon-fields\core\Field\Field.php:262
actionadmin_print_footer_scriptsvendor-dist\htmlburger\carbon-fields\core\Field\Field.php:263
actionadmin_print_footer_scriptsvendor-dist\htmlburger\carbon-fields\core\Field\Field.php:277
actionadmin_footervendor-dist\htmlburger\carbon-fields\core\Field\Rich_Text_Field.php:74
filteruser_can_richeditvendor-dist\htmlburger\carbon-fields\core\Field\Rich_Text_Field.php:91
actionmedia_buttonsvendor-dist\htmlburger\carbon-fields\core\Field\Rich_Text_Field.php:124
actionwpvendor-dist\htmlburger\carbon-fields\core\Field\Scripts_Field.php:29
actionwidgets_initvendor-dist\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:16
actionadmin_enqueue_scriptsvendor-dist\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:18
filtercarbon_fields_sidebar_default_optionsvendor-dist\htmlburger\carbon-fields\core\Libraries\Sidebar_Manager\Sidebar_Manager.php:21
actionafter_setup_themevendor-dist\htmlburger\carbon-fields\core\Loader\Loader.php:38
actioninitvendor-dist\htmlburger\carbon-fields\core\Loader\Loader.php:39
actionrest_api_initvendor-dist\htmlburger\carbon-fields\core\Loader\Loader.php:40
actioncarbon_fields_fields_registeredvendor-dist\htmlburger\carbon-fields\core\Loader\Loader.php:41
actionadmin_enqueue_scriptsvendor-dist\htmlburger\carbon-fields\core\Loader\Loader.php:42
actionadmin_print_footer_scriptsvendor-dist\htmlburger\carbon-fields\core\Loader\Loader.php:43
actionadmin_print_footer_scriptsvendor-dist\htmlburger\carbon-fields\core\Loader\Loader.php:44
actionedit_form_after_titlevendor-dist\htmlburger\carbon-fields\core\Loader\Loader.php:45
filtercarbon_fields_container_static_condition_typesvendor-dist\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:221
filtercarbon_fields_post_meta_container_static_condition_typesvendor-dist\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:225
filtercarbon_fields_post_meta_container_dynamic_condition_typesvendor-dist\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:226
filtercarbon_fields_term_meta_container_static_condition_typesvendor-dist\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:227
filtercarbon_fields_term_meta_container_dynamic_condition_typesvendor-dist\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:228
filtercarbon_fields_user_meta_container_static_condition_typesvendor-dist\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:229
filtercarbon_fields_user_meta_container_dynamic_condition_typesvendor-dist\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:230
filtercarbon_fields_theme_options_container_static_condition_typesvendor-dist\htmlburger\carbon-fields\core\Provider\Container_Condition_Provider.php:231
actionrest_api_initvendor-dist\htmlburger\carbon-fields\core\REST_API\Decorator.php:30
actionrest_api_initvendor-dist\htmlburger\carbon-fields\core\REST_API\Router.php:52
filtercarbon_fields_datastore_storage_arrayvendor-dist\htmlburger\carbon-fields\core\Service\Legacy_Storage_Service_v_1_5.php:56
filterget_meta_sqlvendor-dist\htmlburger\carbon-fields\core\Service\Meta_Query_Service.php:39
actionpre_get_postsvendor-dist\htmlburger\carbon-fields\core\Service\Meta_Query_Service.php:40
actionpre_get_termsvendor-dist\htmlburger\carbon-fields\core\Service\Meta_Query_Service.php:41
actionpre_get_usersvendor-dist\htmlburger\carbon-fields\core\Service\Meta_Query_Service.php:42
actioncarbon_fields_fields_registeredvendor-dist\htmlburger\carbon-fields\core\Service\REST_API_Service.php:38
filtercarbon_get_post_meta_post_idvendor-dist\htmlburger\carbon-fields\core\Service\Revisions_Service.php:11
actioncarbon_fields_post_meta_container_savedvendor-dist\htmlburger\carbon-fields\core\Service\Revisions_Service.php:12
filter_wp_post_revision_fieldsvendor-dist\htmlburger\carbon-fields\core\Service\Revisions_Service.php:13
filter_wp_post_revision_fieldsvendor-dist\htmlburger\carbon-fields\core\Service\Revisions_Service.php:14
actionwp_restore_post_revisionvendor-dist\htmlburger\carbon-fields\core\Service\Revisions_Service.php:15
filterwp_save_post_revision_check_for_changesvendor-dist\htmlburger\carbon-fields\core\Service\Revisions_Service.php:16
actionadmin_noticesvendor-dist\wearerequired\wp-requirements-check\WP_Requirements_Check.php:69
actionadmin_noticesvendor-dist\wearerequired\wp-requirements-check\WP_Requirements_Check.php:98
actionadmin_noticesvendor-dist\wearerequired\wp-requirements-check\WP_Requirements_Check.php:153
actionadmin_noticesvendor-dist\wp-user-manager\wp-notices\wp-notices.php:71
actionadmin_print_scriptsvendor-dist\wp-user-manager\wp-notices\wp-notices.php:72
actionadmin_menuvendor-dist\wp-user-manager\wp-optionskit\wp-optionskit.php:133
filteradmin_body_classvendor-dist\wp-user-manager\wp-optionskit\wp-optionskit.php:134
actionadmin_enqueue_scriptsvendor-dist\wp-user-manager\wp-optionskit\wp-optionskit.php:135
actionrest_api_initvendor-dist\wp-user-manager\wp-optionskit\wp-optionskit.php:136
filterblock_categories_allvendor-dist\wp-user-manager\wpum-blocks\blocks-loader.php:43
actionenqueue_block_editor_assetsvendor-dist\wp-user-manager\wpum-blocks\blocks-loader.php:51
actionwp_loadedvendor-dist\wp-user-manager\wpum-blocks\blocks-loader.php:52
actionrest_api_initvendor-dist\wp-user-manager\wpum-blocks\blocks-loader.php:53
actionrender_blockvendor-dist\wp-user-manager\wpum-blocks\blocks-loader.php:54
actionwidget_display_callbackvendor-dist\wp-user-manager\wpum-blocks\blocks-loader.php:55
actionwidget_update_callbackvendor-dist\wp-user-manager\wpum-blocks\blocks-loader.php:56
filterwpum_blocksvendor-dist\wp-user-manager\wpum-blocks\includes\classes\Blocks\AbstractBlock.php:34
actioninitvendor-dist\wp-user-manager\wpum-blocks\includes\classes\Loader.php:41
Maintenance & Trust

WP User Manager – User Profile Builder & Membership Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.4
Downloads688K

Community Trust

Rating94/100
Number of ratings347
Active installs10K
Developer Profile

WP User Manager – User Profile Builder & Membership Developer Profile

WP User Manager

3 plugins · 10K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
282 days
View full developer profile
Detection Fingerprints

How We Detect WP User Manager – User Profile Builder & Membership

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-user-manager/assets/css/admin/addons.css/wp-content/plugins/wp-user-manager/assets/js/admin/admin-menus.min.js
Script Paths
/wp-content/plugins/wp-user-manager/assets/js/admin/admin-menus.min.js
Version Parameters
wp-user-manager/assets/css/admin/addons.css?ver=wp-user-manager/assets/js/admin/admin-menus.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpum-addonswpum-link-logout-togglewpum-link-visibility-togglewpum-link-visibility-roles
Data Attributes
wpum-link-logout-togglewpum-link-visibility-togglewpum-link-visibility-roles
JS Globals
WPUM_VERSION
REST Endpoints
/wp-json/wp/v2/edd-addons
FAQ

Frequently Asked Questions about WP User Manager – User Profile Builder & Membership