Descripción
User Profile & Membership Plugin for WordPress
The ultimate user profile & membership plugin for WordPress. The plugin makes it a breeze for users to sign-up and become members of your website. The plugin allows you to add beautiful user profiles to your site and is designed for creating advanced online communities and membership sites. Lightweight and highly extendible, Ultimate Member will enable you to create almost any type of site where users can join and become members with absolute ease.
Las características del plugin incluyen:
- Perfiles de usuario en la vista pública
- Registro de usuario en la vista pública
- Acceso de usuario en la vista pública
- Campos de formulario personalizados
- Lógica condicional para campos de formulario
- Maquetador de formularios de arrastrar y soltar
- Página de cuenta de usuario
- Perfiles de usuario personalizados
- Directorios de miembros
- Correos electrónicos del usuario
- Restricción de contenido
- Conditional nav menus
- Mostrar entradas de autor y comentarios en los perfiles de usuario
- Amigable para desarrolladores con docenas de acciones y filtros
Lee sobre todas las características del plugins en Ultimate Member
Extensiones de pago
Ultimate Member has a range of extensions that allow you to extend the power of the plugin. You can purchase all of these extensions at a significant discount with one of our paid plans or you can purchase extensions individually.
- Zapier – Allow to integrate the Zapier popular apps with Ultimate Member
- Stripe – Sell paid memberships to access your website via Stripe subscriptions
- User Notes – Allow users to create public and private notes from their profile
- Profile Tabs – Allow to add the custom tabs to profiles
- User Locations – Allow to display users on a map on the member directory page and allow users to add their location via their profile
- Unsplash – Allow users to select a profile cover photo from Unsplash from their profile
- User Bookmarks – Allow users to bookmark content from your website
- User Photos – Allow users to upload photos to their profile
- Groups – Allow users to create and join groups around shared topics, interests etc.
- Private Content – Display private content to logged in users that only they can access
- User Tags – Te permite añadir un sistema de etiquetas de usuario a tu sitio
- Social Activity – Let users create public wall posts & see the activity of other users
- WooCommerce – Allow you to integrate WooCommerce with Ultimate Member
- Private Messages – Add a private messaging system to your site & allow users to message each other
- Followers – Allow users to follow each other on your site and protect their profile information
- Real-time Notifications – Add a notifications system to your site so users can receive real-time notifications
- Social Login – Let users register & login to your site via Facebook, Twitter, G+, LinkedIn, Instagram and Vkontakte (VK.com)
- bbPress – With the bbPress extension you can beautifully integrate Ultimate Member with bbPress
- MailChimp – Allow users to subscribe to your MailChimp lists when they signup on your site and sync user meta to MailChimp
- User Reviews – Allow users to rate & review each other using a 5 star rate/review system
- Verified Users – Add a user verification system to your site so user accounts can be verified
- myCRED – With the myCRED extension you can integrate Ultimate Member with the popular myCRED points management plugin
- Notices – Alert users to important information using conditional notices
- Profile Completeness – Encourage or force users to complete their profiles with the profile completeness extension
- Friends – Permite a los usuarios convertirse en amigos enviando y aceptando o rechanzando solicitudes de amistad
Extensiones gratuitas
- JobsBoardWP – This free extension integrates Ultimate Member with the job board plugin JobBoardWP.
- ForumWP – This free extension integrates Ultimate Member with the forum plugin ForumWP.
- Terms & Conditions – Add a terms and condition checkbox to your registration forms & require users to agree to your T&Cs before registering on your site.
- Google reCAPTCHA – Stop bots on your registration & login forms with Google reCAPTCHA
- Online Users – Display what users are online with this extension
Tema
Our official theme is purpose built for websites that have logged in and out users. The theme has deep integration with Ultimate Member plugin and the extensions, different header designs for logged-in/out users and works alongside the Beaver Builder and Elementor page builders.
Our other plugins
In addition to Ultimate Member, we also have two other plugins: ForumWP and JobBoardWP.
ForumWP
ForumWP is a forum plugin which adds an online forum to your website, allowing users to create topics and write replies. Forums are a great way to build and grow an online community.
JobBoardWP
JobBoardWP is a job board plugin which adds a modern job board to your website. Display job listings and allow employers to submit and manage jobs all from the front-end.
Desarrollo * Traducciones
Si eres un desarrollador y quieres contribuir al código fuente del plugin, puedes hacerlo a través de nuestro repositorio de GitHub.
Want to add a new language to Ultimate Member? Great! You can contribute via translate.wordpress.org.
If you are a developer and you need to know the list of UM Hooks, make this via our Hooks Documentation or Hooks Documentation v2.
If you are a developer and you need to know the structure of our code, make this via our Documentation API.
Documentación y soporte
¿Tienes un problema o necesitas ayuda con Ultimate Member? Dirígete a nuestra documentación y realizar una búsqueda en la base de conocimientos. Si no puedes encontrar una solución a tu problema, puedes crear un tique de soporte.
Capturas
Bloques
Este plugin proporciona 4 bloques.
- Account Displaying the account page of the current user
- Form Choose display form
- Member Directory Choose display directory
- Password Reset Displaying the password reset form
Instalación
- Activar el plugin
- Eso es todo. Ve a «Ultimate Member» > «Ajustes» para personalizar las opciones del plugin
- Para obtener más detalles, visita la documentación oficial.
Preguntas frecuentes
-
¿Necesito saber algo de código para usar este plugin?
-
No, hemos construido «Ultimate Member» para ser extremadamente fácil de usar y no requiere que construyas «shortcodes» manualmente o tengas ningún conocimiento de código.
-
¿«Ultimate Member» es adaptable en móviles?
-
Sí. «Ultimate Member» está diseñado para adaptarse perfectamente a cualquier resolución de pantalla. Incluye diseños específicos para teléfonos, tabletas y equipos de sobremesa.
-
¿«Ultimate Member» es compatible con multisitios?
-
Sí. «Ultimate Member» funciona muy bien en instalaciones de WordPress de sitio único y de sitios múltiples.
-
¿El plugin funciona con cualquier tema de WordPress?
-
Sí. «Ultimate Member» trabajará con cualquier tema debidamente codificado. Sin embargo, algunos temas pueden causar conflictos con el plugin. Si encuentras un problema de estilo con tu tema, por favor crea una publicación en el foro de la comunidad.
-
¿El plugin funciona con los plugins de caché?
-
El plugin funciona con plugins de caché populares al excluir automáticamente las páginas de «Ultimate Member» de la caché. Esto garantiza que otros visitantes de una página no vean la información privada de otro usuario. Sin embargo, si añades características de «Ultimate Member» a otras páginas, debes excluir esas páginas de la caché a través del panel de configuración de tu plugin de caché.
-
Does Ultimate Member restrict access to wp-login.php when the plugin is active?
-
The plugin does not restrict access to the wp-login.php page when active, so that our plugin does not interfere with the existing functionality of a website or other plugins that may utilise the default login page. If you wish to restrict access to the wp-login.php page you can use a plugin such as WPS Hide Login or another plugin that removes the ability to login via wp-login.php.
-
Are Ultimate Member Login/Registration pages required?
-
No, you do not need to use our plugin’s login or registration pages and can use another plugin or the default WordPress methods for user registration and login.
-
Are additional PHP modules necessary for the plugin to work correctly?
-
No specific extensions are needed. But we highly recommended keep active these PHP modules:
mbstring,json,dom,exif,gd,fileinfo,curl,iconv. wp-admin > Tools > Site Health page has a summary about your installation and required modules. All major extensions are listed here.
Reseñas
Colaboradores y desarrolladores
«Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin» es un software de código abierto. Las siguientes personas han colaborado con este plugin.
Colaboradores«Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin» ha sido traducido a 30 idiomas locales. Gracias a los traductores por sus contribuciones.
¿Interesado en el desarrollo?
Revisa el código , echa un vistazo al repositorio SVN o suscríbete al registro de desarrollo por RSS.
Registro de cambios
Important:
IMPORTANT: PLEASE UPDATE THE PLUGIN TO AT LEAST VERSION 2.6.7 IMMEDIATELY. VERSION 2.6.7 PATCHES SECURITY PRIVILEGE ESCALATION VULNERABILITY. PLEASE SEE THIS ARTICLE FOR MORE INFORMATION
2.14.0 2026-09-29
Enhancements
- Added:
$form_idparameter to the action hooksum_before_form,um_before_{$mode}_fields,um_main_{$mode}_fields,um_after_form_fields,um_after_{$mode}_fieldsandum_after_form. - Added: Action hook
um_before_render_dynamic_modal_contentfor 3rd-party integration when the admin popup is opened. - Added: Filter hooks
um_email_validation_real_error_codesandum_email_validation_error_messagefor 3rd-party integration to change or make visible the real error message for email fields validation. - Added: Threads field support in the UM Forms and Social Icons meta-row.
Bugfixes
- Fixed: Security issue related to an unauthenticated PHP Object Injection vulnerability. (Reported by Ananda Dhakal (Patchstack)). Added
um_maybe_unserialize()function. - Fixed: Security issue related to administrator Stored SQL Injection via Directory Search-Field Identifiers. (Reported by Ananda Dhakal (Patchstack)). Added sanitizing for the searching fields in the member directory.
- Fixed: Security issue related to an unauthenticated Improper Enforcement of Behavioral Workflow vulnerability. (Reported by Ananda Dhakal (Patchstack)). Added unique nonce fields and attributes for requests.
- Fixed: CVE-2026-96270 security issue. Added sanitizing for the form_id attribute during the Ultimate Member forms submission. (Reported by Wordfence).
- Fixed: CVE-2026-93428 security issue. Fixed fields privacy when displaying the User Profile fields. (Reported by Wordfence).
- Fixed: Security issue related to Privilege Escalation. Fixed user account submission and nonce security. Reset the user if it hasn’t the ability to download the file. (Reported by Intrudify (Patchstack)).
- Fixed:
is_url()validation for the social links fields. - Fixed:
unique_emailvalidation. Parse primary and secondary email fields to make the email unique between them.
Templates Requiring Update
- profile/comments.php
- profile/posts.php
- login.php
- members.php
- profile.php
- register.php
Deprecated
- Deprecated:
UM()->check_ajax_nonceandUM()->admin()->check_ajax_nonce()functions. Use WordPress nativewp_verify_nonce(),check_admin_referer()andcheck_ajax_referer()instead with unique nonce field values. Left them now for backward compatibility. - Deprecated: Using
um_admin_scripts.nonceandum_scripts.noncelocalized data in UM scripts. Left them still localized for backward compatibility. - Deprecated: JS common action for
'.um-ajax-action'class. It’s not used anymore in UM core and extensions and can be removed the same as AJAX handler forum_muted_action. - Deprecated: Action hook
um_run_ajax_function__{$hook}used in theum_muted_actionhandler. - Marked as deprecate soon:
in_groupattribute for the fields in the UM Forms builder.
Note: Cached and optimized/minified assets(JS/CSS) must be flushed/re-generated after the upgrade
2.13.1 2026-09-15
Enhancements
- Added: Fallback for
wp-cli/wp-config-transformerlibrary if the wp-config.php file isn’t writable. - Added: Filter hook
um_members_directory_filter_text3rd parameter$is_defaultto check if it’s admin filtering or frontend query. - Added: ‘Administrative capabilities ban’ option enabled by default after the first installation.
- Optimized: Slow SQL query for batch empty account status check.
- Optimized: Redundant SQL calls when editing the Profile page with callback dropdowns. Cached usermeta existence checks per user and key during a single load (Reported by @MissVeronica, author @faisalahammad).
Bugfixes
- Fixed: Security issue related to an unauthenticated visitor can store JavaScript that runs in an administrator’s session, through their own profile name. (Reported by Karthik Ramakrishnan and WPScan team). Fixed
um_convert_tags()function and applied the escapers throughout the placeholder replacement. - Fixed: Using LIKE compare for the text-type filters with custom usermeta table (Reported by @MissVeronica, author @faisalahammad).
- Fixed: «Can user edit this field?» field setting displaying only for the User Profile form fields.
- Fixed: Getting the pages list in the wp-admin UM > Settings > General > Pages section.
- Fixed: Displaying the field-type time on the User Profile page.
- Fixed: Using
illegal_user_loginsfor the current admin user with the username specified in the illegal user logins list.
Deprecated
- Deprecated: Filter hook
um_members_directory_filter_text_meta_valueis fully deprecated, replacement isn’t required for the text-type filter field.
2.13.0 2026-08-24
Enhancements
- Added: Using
illegal_user_loginsfilter to sanitize theuser_loginfield value during registration or upgrade. - Added: Using
wp-cli/wp-config-transformerlibrary to set Ultimate Member > API keys settings constants in wp-config.php instead of storing them in DB. - Added: New user-capabilities functions
UM()->common()->users()->can_view_user(),UM()->common()->users()->get_privacy_setting(),UM()->common()->users()->is_user_profile_private(),UM()->common()->users()->get_restricted_privacy_notice(),UM()->common()->users()->can_view_private_user_profile(),UM()->common()->users()->can_view_user_profile(). The future replacement for theum_can_view_profile()helper with different cases to check. - Updated: Version of the WordPress native excluded functions to avoid the using them in the callbacks.
Bugfixes
- Fixed:
WP_Filesystem()initialization optimization. InitWP_Filesystem()only once when it’s necessary. - Fixed: Redirect on non-main queries (breaks Spectra and block themes). Added conditional check for the main query (based on @faisalahammad suggestions).
- Fixed: Registration form infinite loop – gdpr-register.php calls
the_contentrecursively causing PHP fatal error. Excluded predefined UM pages and pages with [ultimatemember] shortcode from the list, render empty content for such pages if they are already selected to avoid PHP error (based on @faisalahammad suggestions). - Fixed: Causes site-wide
rest_cookie_invalid_nonceon all authenticated REST requests. Refactored admin notice handling to enhance security and flexibility. Removed using localizedum_admin_scripts.nonceglobally on wp-admin. It’s localized only on UM wp-admin pages. (based on @michaeldavisdcpersonal report and @faisalahammad suggestions). - Fixed: Security issue when an unauthenticated visitor can read the content of comments awaiting moderation. (Reported by Alessandro Greco (Aleff) and Giovambattista Ianni, University of Calabria (UNICAL)).
- Fixed: Security issue related to an unauthenticated privilege escalation through the profile form role field. (Reported by Jakub Herman).
- Fixed: Security issue, CVE ID: CVE-2026-18547. Used ‘user_input’ allowed a tag list to sanitize HTML-enabled textarea fields. Deprecated Pickadate.JS and Pickatime.JS libraries for User Forms fields.
- Fixed: Member Directory type-button styles.
- Fixed: Added fallback for the date and time fields to show date and time using the WordPress native format.
Templates Requiring Update
- gdpr-register.php
- profile.php
Deprecated
- Deprecated: Pickadate.JS and Pickatime.JS libraries for User Forms fields. Used HTML native
<input type="date" />and<input type="time" />instead.
Note: Cached and optimized/minified assets(JS/CSS) must be flushed/re-generated after the upgrade












