Descrição
O Ultimate Member cria perfis de usuário front-end no WordPress, gerando páginas de cadastro, login, perfil e diretório de membros configuráveis por arrastar e soltar no construtor de formulários nativo. Você define funções personalizadas, restringe conteúdo por papel, monta listagens filtráveis de usuários e habilita uploads de avatar e capa diretamente no perfil público, transformando o site em uma plataforma de comunidade.
Características Principais
- Construtor de formulários drag-and-drop
Monta formulários de registro, login e edição de perfil com campos personalizados arrastáveis. - Diretórios de membros filtráveis
Exibe listagens de usuários com busca, ordenação e filtros por meta dados cadastrados. - Funções e permissões customizadas
Cria papéis específicos da comunidade com regras de acesso a conteúdo, páginas e ações. - Restrição de conteúdo condicional
Bloqueia páginas, posts, categorias e taxonomias por função, status de login ou critérios meta. - Páginas de perfil front-end
Gera perfis públicos com abas, fotos de capa, avatares e campos meta exibidos no site.
Benefícios do Ultimate Member
- Comunidade ativa no próprio site
Mantém usuários engajados sem depender de redes sociais externas para interação. - Cadastro adaptado ao seu nicho
Coleta exatamente os dados que importam para o tipo de comunidade que você opera. - Controle granular de acesso
Decide quem vê o quê, reservando áreas exclusivas para grupos específicos de membros. - Implantação sem código
Configura toda a estrutura de membros pelo painel, dispensando desenvolvimento personalizado.
Para Quem é Indicado?
- Criadores de comunidades online, redes sociais de nicho e fóruns temáticos.
- Plataformas de associação, clubes de assinatura e áreas exclusivas para membros.
- Sites educacionais, profissionais e diretórios que precisam de perfis públicos detalhados.
Quem precisa transformar um site WordPress em uma rede de membros completa encontra no Ultimate Member a base para registro, perfis públicos, diretórios e controle de acesso, tudo gerenciado pelo painel. A combinação entre construtor de formulários e regras de restrição por função abre espaço para comunidades de aprendizado, associações profissionais e portais privados que dependem de identidade própria para cada usuário.
Perguntas Frequentes
O plugin Ultimate Member é GPL?
Sim. O Ultimate Member é distribuído sob a licença GPL (GNU General Public License). Você pode usar, modificar e redistribuir legalmente, em quantos sites quiser.
Posso usar o plugin Ultimate Member em mais de um site?
Sim. Você pode instalar o Ultimate Member em quantos sites quiser. Só as atualizações automáticas pelo Ultrapack Auto Updater têm limite: de 3 a 80 sites, conforme o plano.
Quanto custa o plugin Ultimate Member no Ultrapack?
O Ultimate Member sai por R$ 14,90 na compra avulsa, e também está incluído nos planos de assinatura a partir de R$59/mês (VIP I).
O plugin Ultimate Member inclui atualizações?
Sim. A versão atual do Ultimate Member é a 2.14.0, publicada no Ultrapack em 01/10/2026. Assinantes atualizam direto do painel do WordPress com o UAU (Ultrapack Auto Updater).
O plugin Ultimate Member é seguro para baixar e instalar no meu WordPress?
Sim. Cada versão do Ultimate Member passa por varredura de malware (ClamAV e regras YARA, no UltraHub) antes de ser publicada.
Quais são os requisitos do plugin Ultimate Member?
Requer WordPress 6.2 ou superior e PHP 7.0 ou superior. Testado até o WordPress 7.1.
O que mudou nesta versão
Versão 2.14.0 2026-09-29
- Enhancements
- Added: `$form_id` parameter to the action hooks `um_before_form`, `um_before_{$mode}_fields`, `um_main_{$mode}_fields`, `um_after_form_fields`, `um_after_{$mode}_fields` and `um_after_form`.
- Added: Action hook `um_before_render_dynamic_modal_content` for 3rd-party integration when the admin popup is opened.
- Added: Filter hooks `um_email_validation_real_error_codes` and `um_email_validation_error_message` for 3rd-party integration to change or make visible the real error message for email fields validation.
- Added: Threads field support in the UM Forms and Social Icons meta-row.
- Bugfixes
- Fixed: Security issue related to an unauthenticated PHP Object Injection vulnerability. (Reported by Ananda Dhakal (Patchstack)). Added `um_maybe_unserialize` function.
- Fixed: Security issue related to administrator Stored SQL Injection via Directory Search-Field Identifiers. (Reported by Ananda Dhakal (Patchstack)). Added sanitizing for the searching fields in the member directory.
- Fixed: Security issue related to an unauthenticated Improper Enforcement of Behavioral Workflow vulnerability. (Reported by Ananda Dhakal (Patchstack)). Added unique nonce fields and attributes for requests.
- Fixed: CVE-2026-96270 security issue. Added sanitizing for the form_id attribute during the Ultimate Member forms submission. (Reported by Wordfence).
- Fixed: CVE-2026-93428 security issue. Fixed fields privacy when displaying the User Profile fields. (Reported by Wordfence).
- Fixed: Security issue related to Privilege Escalation. Fixed user account submission and nonce security. Reset the user if it hasn't the ability to download the file. (Reported by Intrudify (Patchstack)).
- Fixed: `is_url` validation for the social links fields.
- Fixed: `unique_email` validation. Parse primary and secondary email fields to make the email unique between them.
- Templates Requiring Update
- profile/comments.php
- profile/posts.php
- login.php
- members.php
- profile.php
- register.php
- Deprecated
- Deprecated: `UM->check_ajax_nonce` and `UM->admin->check_ajax_nonce` functions. Use WordPress native `wp_verify_nonce`, `check_admin_referer` and `check_ajax_referer` instead with unique nonce field values. Left them now for backward compatibility.
- Deprecated: Using `um_admin_scripts.nonce` and `um_scripts.nonce` localized data in UM scripts. Left them still localized for backward compatibility.
- Deprecated: JS common action for `'.um-ajax-action'` class. It's not used anymore in UM core and extensions and can be removed the same as AJAX handler for `um_muted_action`.
- Deprecated: Action hook `um_run_ajax_function__{$hook}` used in the `um_muted_action` handler.
- Marked as deprecate soon: `in_group` attribute for the fields in the UM Forms builder.
- Note: Cached and optimized/minified assets(JS/CSS) must be flushed/re-generated after the upgrade
Versão 2.13.1 2026-09-15
- Enhancements
- Added: Fallback for `wp-cli/wp-config-transformer` library if the wp-config.php file isn't writable.
- Added: Filter hook `um_members_directory_filter_text` 3rd parameter `$is_default` to check if it's admin filtering or frontend query.
- Added: 'Administrative capabilities ban' option enabled by default after the first installation.
- Optimized: Slow SQL query for batch empty account status check.
- Optimized: Redundant SQL calls when editing the Profile page with callback dropdowns. Cached usermeta existence checks per user and key during a single load (Reported by @MissVeronica, author @faisalahammad).
- Bugfixes
- Fixed: Security issue related to an unauthenticated visitor can store JavaScript that runs in an administrator's session, through their own profile name. (Reported by Karthik Ramakrishnan and WPScan team). Fixed `um_convert_tags` function and applied the escapers throughout the placeholder replacement.
- Fixed: Using LIKE compare for the text-type filters with custom usermeta table (Reported by @MissVeronica, author @faisalahammad).
- Fixed: "Can user edit this field?" field setting displaying only for the User Profile form fields.
- Fixed: Getting the pages list in the wp-admin UM > Settings > General > Pages section.
- Fixed: Displaying the field-type time on the User Profile page.
- Fixed: Using `illegal_user_logins` for the current admin user with the username specified in the illegal user logins list.
- Deprecated
- Deprecated: Filter hook `um_members_directory_filter_text_meta_value` is fully deprecated, replacement isn't required for the text-type filter field.
Versão 2.13.0 2026-08-24
- Enhancements
- Added: Using `illegal_user_logins` filter to sanitize the `user_login` field value during registration or upgrade.
- Added: Using `wp-cli/wp-config-transformer` library to set Ultimate Member > API keys settings constants in wp-config.php instead of storing them in DB.
- Added: New user-capabilities functions `UM->common->users->can_view_user`, `UM->common->users->get_privacy_setting`, `UM->common->users->is_user_profile_private`, `UM->common->users->get_restricted_privacy_notice`, `UM->common->users->can_view_private_user_profile`, `UM->common->users->can_view_user_profile`. The future replacement for the `um_can_view_profile` helper with different cases to check.
- Updated: Version of the WordPress native excluded functions to avoid the using them in the callbacks.
- Bugfixes
- Fixed: `WP_Filesystem` initialization optimization. Init `WP_Filesystem` only once when it's necessary.
- Fixed: Redirect on non-main queries (breaks Spectra and block themes). Added conditional check for the main query (based on @faisalahammad suggestions).
- Fixed: Registration form infinite loop - gdpr-register.php calls `the_content` recursively causing PHP fatal error. Excluded predefined UM pages and pages with [ultimatemember] shortcode from the list, render empty content for such pages if they are already selected to avoid PHP error (based on @faisalahammad suggestions).
- Fixed: Causes site-wide `rest_cookie_invalid_nonce` on all authenticated REST requests. Refactored admin notice handling to enhance security and flexibility. Removed using localized `um_admin_scripts.nonce` globally on wp-admin. It's localized only on UM wp-admin pages. (based on @michaeldavisdcpersonal report and @faisalahammad suggestions).
- Fixed: Security issue when an unauthenticated visitor can read the content of comments awaiting moderation. (Reported by Alessandro Greco (Aleff) and Giovambattista Ianni, University of Calabria (UNICAL)).
- Fixed: Security issue related to an unauthenticated privilege escalation through the profile form role field. (Reported by Jakub Herman).
- Fixed: Security issue, CVE ID: CVE-2026-18547. Used 'user_input' allowed a tag list to sanitize HTML-enabled textarea fields. Deprecated Pickadate.JS and Pickatime.JS libraries for User Forms fields.
- Fixed: Member Directory type-button styles.
- Fixed: Added fallback for the date and time fields to show date and time using the WordPress native format.
- Templates Requiring Update
- gdpr-register.php
- profile.php
- Deprecated
- Deprecated: Pickadate.JS and Pickatime.JS libraries for User Forms fields. Used HTML native ` ` and ` ` instead.
- Note: Cached and optimized/minified assets(JS/CSS) must be flushed/re-generated after the upgrade
- [See changelog for all versions]
Notas de versão publicadas pelo desenvolvedor.
Como instalar
Atualização automática: este item é atualizado pelo Ultrapack Auto Updater. Com ele instalado, a versão nova aparece no seu painel como qualquer outra atualização do WordPress (como configurar).
O item já vem com as funções liberadas. A tela de licença existe só para o plugin parar de pedir.
- Baixe o arquivo
ultimate-member.zip. - No painel do WordPress, vá em Plugins > Adicionar novo > Enviar plugin.
- Selecione o arquivo
ultimate-member.zip, clique em Instalar agora e depois em Ativar. - Abra a tela de licença do plugin e digite qualquer código. Onde houver campo de e-mail, serve qualquer e-mail.
Requisitos: Requer WordPress 6.2 ou superior e PHP 7.0 ou superior. Testado até o WordPress 7.1.
- Não há ativação junto ao desenvolvedor. As atualizações chegam pelo Ultrapack Auto Updater, quando o item tem esse recurso.
- Este item já vem liberado. Se alguma tela pedir licença, digite qualquer código; onde houver campo de e-mail, serve qualquer e-mail.
Travou em algum passo? Abra um chamado dizendo em qual deles parou.

UAU Ready