Ultimate Member icon

Release v2.11.3

Ultimate Member v2.11.3

What's new in v2.11.3

Ultimate Member v2.11.3 was released on . The easiest way to create powerful online communities and beautiful user profiles with WordPress. See the full changelog below and compare with the complete version history.

Release details

Released
3.6 MB
File unavailable

Changelog

Other
  • *Enhancements**
  • *Bugfixes**
  • *Templates Requiring Update**
  • members.php
  • message.php
  • restricted-blog.php
  • restricted-taxonomy.php
  • *Note: Cached and optimized/minified assets(JS/CSS) must be flushed/re-generated after the upgrade**
Added
  • UM > Settings > Advanced > APIs section for set available APIs settings.
  • GoogleMaps API setting when it's available.
  • Function `UM()->mail()->enabled_email()` for checking if the email notification is enabled by the user.
  • `color` type of sanitize settings saved in wp-admin.
  • Checking array type of submission data when `url` type of sanitize is used in wp-admin.
  • Enhance UM form sanitization filter with $form_data param. Added the $form_data parameter to the `um_sanitize_form_submission` filter.
  • Option for special character requirement for passwords. It's situated in "General > Users > Password requires special character" (based on @faisalahammad suggestions)
  • Filter hook `um_before_account_delete_text` for changing before delete account text by 3rd-party plugins. End-customers can use it for translations.
  • Filter hook `um_custom_{$message_key}` (`um_custom_pending_message`, `um_custom_checkmail_message`) for changing after-registration message based on the user status by 3rd-party plugins. End-customers can use it for translations.
  • Filter hook `um_convert_tags_blacklist_fields` For 3rd-party integrations to control the usermeta keys in `um_convert_tags()` function.
  • `.um-display-none` CSS utility + `umShow()/umHide()/umToggle()` jQuery helpers.
  • `um-notice` JS library.
Fixed
  • Security issue, CVE ID: CVE-2026-4248. Added blacklist filter for convert_tag replace placeholders function.
  • HTML sanitization logic for textarea-type custom fields with enabled HTML using setting.
  • WP editor formatting to prevent incorrect HTML entity conversion when using html-mode in the textarea-type custom fields. Applied and removed this filter dynamically to avoid interfering with other processes.
  • Dynamic string translation pattern and improve escaping. Replaced incorrect __('%s') pattern. (@faisalahammad)
  • `wp_die()` function triggering on the frontend actions. Added UM notice above the User Profile page. (based on @faisalahammad suggestions)
  • Password reset key handling for multiple users. Previously, the static reset key caused issues when handling password resets for multiple users simultaneously.
  • `um_trim_string()` function for using with UTF-8 symbols.
  • PHP Notice: Function WP_Scripts::add was called incorrectly.

Compatibility

Requires WordPress
6.2
Tested up to
7.0
Requires PHP
7.0

Verified safe

Ultimate Member v2.11.3 scanned clean with no security threats detected.

View full scan report