Description
Ultimate Member creates front-end user profiles in WordPress, generating configurable registration, login, profile, and member directory pages via drag-and-drop in the native form builder. You define custom roles, restrict content by role, build filterable user listings, and enable avatar and cover uploads directly on the public profile, turning the site into a community platform.
Key Features
- Drag-and-drop form builder
Build registration, login, and profile editing forms with draggable custom fields. - Filterable member directories
Display user listings with search, sorting, and filters by registered meta data. - Custom roles and permissions
Create community-specific roles with access rules for content, pages, and actions. - Conditional content restriction
Block pages, posts, categories, and taxonomies by role, login status, or meta criteria. - Front-end profile pages
Generate public profiles with tabs, cover photos, avatars, and meta fields displayed on the site.
Benefits of Ultimate Member
- Active community on your own site
Keeps users engaged without relying on external social networks for interaction. - Registration tailored to your niche
Collects exactly the data that matters for the type of community you run. - Granular access control
Decide who sees what, reserving exclusive areas for specific member groups. - No-code deployment
Configure the entire membership structure from the dashboard, no custom development required.
Who Is It For?
- Creators of online communities, niche social networks, and topic-based forums.
- Membership platforms, subscription clubs, and exclusive member-only areas.
- Educational, professional, and directory sites that need detailed public profiles.
Anyone who needs to turn a WordPress site into a full membership network will find in Ultimate Member the foundation for registration, public profiles, directories, and access control, all managed from the dashboard. The combination of a form builder and role-based restriction rules opens the door to learning communities, professional associations, and private portals that rely on a distinct identity for each user.
Frequently asked questions
Is Ultimate Member GPL-licensed?
Yes. Ultimate Member is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.
Can I use Ultimate Member on multiple sites?
Yes. You can install Ultimate Member on as many sites as you want. Only automatic updates through Ultrapack Auto Updater have a limit: from 3 to 80 sites, depending on the plan.
How much does Ultimate Member cost at Ultrapack?
Ultimate Member costs US$2.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).
Does Ultimate Member include updates?
Yes. The current version of Ultimate Member is 2.14.0, published at Ultrapack on Oct 1, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).
Is Ultimate Member scanned before publication?
Yes. Every version of Ultimate Member goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.
What are the requirements for the plugin Ultimate Member?
Requires WordPress 6.2 or higher and PHP 7.0 or higher. Tested up to WordPress 7.1.
What changed in this version
Version 2.14.0 2026-09-29
- Enhancements
- Added: `$form_id` parameter to the action hooks `um_before_form`, `um_before_{$mode}_fields`, `um_main_{$mode}_fields`, `um_after_form_fields`, `um_after_{$mode}_fields` and `um_after_form`.
- Added: Action hook `um_before_render_dynamic_modal_content` for 3rd-party integration when the admin popup is opened.
- Added: Filter hooks `um_email_validation_real_error_codes` and `um_email_validation_error_message` for 3rd-party integration to change or make visible the real error message for email fields validation.
- Added: Threads field support in the UM Forms and Social Icons meta-row.
- Bugfixes
- Fixed: Security issue related to an unauthenticated PHP Object Injection vulnerability. (Reported by Ananda Dhakal (Patchstack)). Added `um_maybe_unserialize` function.
- Fixed: Security issue related to administrator Stored SQL Injection via Directory Search-Field Identifiers. (Reported by Ananda Dhakal (Patchstack)). Added sanitizing for the searching fields in the member directory.
- Fixed: Security issue related to an unauthenticated Improper Enforcement of Behavioral Workflow vulnerability. (Reported by Ananda Dhakal (Patchstack)). Added unique nonce fields and attributes for requests.
- Fixed: CVE-2026-96270 security issue. Added sanitizing for the form_id attribute during the Ultimate Member forms submission. (Reported by Wordfence).
- Fixed: CVE-2026-93428 security issue. Fixed fields privacy when displaying the User Profile fields. (Reported by Wordfence).
- Fixed: Security issue related to Privilege Escalation. Fixed user account submission and nonce security. Reset the user if it hasn't the ability to download the file. (Reported by Intrudify (Patchstack)).
- Fixed: `is_url` validation for the social links fields.
- Fixed: `unique_email` validation. Parse primary and secondary email fields to make the email unique between them.
- Templates Requiring Update
- profile/comments.php
- profile/posts.php
- login.php
- members.php
- profile.php
- register.php
- Deprecated
- Deprecated: `UM->check_ajax_nonce` and `UM->admin->check_ajax_nonce` functions. Use WordPress native `wp_verify_nonce`, `check_admin_referer` and `check_ajax_referer` instead with unique nonce field values. Left them now for backward compatibility.
- Deprecated: Using `um_admin_scripts.nonce` and `um_scripts.nonce` localized data in UM scripts. Left them still localized for backward compatibility.
- Deprecated: JS common action for `'.um-ajax-action'` class. It's not used anymore in UM core and extensions and can be removed the same as AJAX handler for `um_muted_action`.
- Deprecated: Action hook `um_run_ajax_function__{$hook}` used in the `um_muted_action` handler.
- Marked as deprecate soon: `in_group` attribute for the fields in the UM Forms builder.
- Note: Cached and optimized/minified assets(JS/CSS) must be flushed/re-generated after the upgrade
Version 2.13.1 2026-09-15
- Enhancements
- Added: Fallback for `wp-cli/wp-config-transformer` library if the wp-config.php file isn't writable.
- Added: Filter hook `um_members_directory_filter_text` 3rd parameter `$is_default` to check if it's admin filtering or frontend query.
- Added: 'Administrative capabilities ban' option enabled by default after the first installation.
- Optimized: Slow SQL query for batch empty account status check.
- Optimized: Redundant SQL calls when editing the Profile page with callback dropdowns. Cached usermeta existence checks per user and key during a single load (Reported by @MissVeronica, author @faisalahammad).
- Bugfixes
- Fixed: Security issue related to an unauthenticated visitor can store JavaScript that runs in an administrator's session, through their own profile name. (Reported by Karthik Ramakrishnan and WPScan team). Fixed `um_convert_tags` function and applied the escapers throughout the placeholder replacement.
- Fixed: Using LIKE compare for the text-type filters with custom usermeta table (Reported by @MissVeronica, author @faisalahammad).
- Fixed: "Can user edit this field?" field setting displaying only for the User Profile form fields.
- Fixed: Getting the pages list in the wp-admin UM > Settings > General > Pages section.
- Fixed: Displaying the field-type time on the User Profile page.
- Fixed: Using `illegal_user_logins` for the current admin user with the username specified in the illegal user logins list.
- Deprecated
- Deprecated: Filter hook `um_members_directory_filter_text_meta_value` is fully deprecated, replacement isn't required for the text-type filter field.
Version 2.13.0 2026-08-24
- Enhancements
- Added: Using `illegal_user_logins` filter to sanitize the `user_login` field value during registration or upgrade.
- Added: Using `wp-cli/wp-config-transformer` library to set Ultimate Member > API keys settings constants in wp-config.php instead of storing them in DB.
- Added: New user-capabilities functions `UM->common->users->can_view_user`, `UM->common->users->get_privacy_setting`, `UM->common->users->is_user_profile_private`, `UM->common->users->get_restricted_privacy_notice`, `UM->common->users->can_view_private_user_profile`, `UM->common->users->can_view_user_profile`. The future replacement for the `um_can_view_profile` helper with different cases to check.
- Updated: Version of the WordPress native excluded functions to avoid the using them in the callbacks.
- Bugfixes
- Fixed: `WP_Filesystem` initialization optimization. Init `WP_Filesystem` only once when it's necessary.
- Fixed: Redirect on non-main queries (breaks Spectra and block themes). Added conditional check for the main query (based on @faisalahammad suggestions).
- Fixed: Registration form infinite loop - gdpr-register.php calls `the_content` recursively causing PHP fatal error. Excluded predefined UM pages and pages with [ultimatemember] shortcode from the list, render empty content for such pages if they are already selected to avoid PHP error (based on @faisalahammad suggestions).
- Fixed: Causes site-wide `rest_cookie_invalid_nonce` on all authenticated REST requests. Refactored admin notice handling to enhance security and flexibility. Removed using localized `um_admin_scripts.nonce` globally on wp-admin. It's localized only on UM wp-admin pages. (based on @michaeldavisdcpersonal report and @faisalahammad suggestions).
- Fixed: Security issue when an unauthenticated visitor can read the content of comments awaiting moderation. (Reported by Alessandro Greco (Aleff) and Giovambattista Ianni, University of Calabria (UNICAL)).
- Fixed: Security issue related to an unauthenticated privilege escalation through the profile form role field. (Reported by Jakub Herman).
- Fixed: Security issue, CVE ID: CVE-2026-18547. Used 'user_input' allowed a tag list to sanitize HTML-enabled textarea fields. Deprecated Pickadate.JS and Pickatime.JS libraries for User Forms fields.
- Fixed: Member Directory type-button styles.
- Fixed: Added fallback for the date and time fields to show date and time using the WordPress native format.
- Templates Requiring Update
- gdpr-register.php
- profile.php
- Deprecated
- Deprecated: Pickadate.JS and Pickatime.JS libraries for User Forms fields. Used HTML native ` ` and ` ` instead.
- Note: Cached and optimized/minified assets(JS/CSS) must be flushed/re-generated after the upgrade
- [See changelog for all versions]
Release notes published by the developer.
How to install
Automatic updates: this item is updated by the Ultrapack Auto Updater. With it installed, the new version shows up in your dashboard like any other WordPress update (how to set it up).
The item already comes with its features enabled. The license screen is there only to stop the plugin from asking.
- Download the file
ultimate-member.zip. - In the WordPress dashboard, go to Plugins > Add New > Upload Plugin.
- Select the file
ultimate-member.zip, click Install Now and then Activate. - Open the plugin license screen and type any code. Where there is an email field, any email works.
Requirements: Requires WordPress 6.2 or higher and PHP 7.0 or higher. Tested up to WordPress 7.1.
- There is no activation with the developer. Updates arrive through the Ultrapack Auto Updater, when the item supports it.
- This item is already activated. If any screen asks for a license, enter any code; any email works in the email field.
Stuck on a step? Open a ticket telling us which one you stopped at.

UAU Ready