الوصف
User Profile & Membership Plugin for WordPress
The ultimate user profile & membership plugin for WordPress. The plugin makes it a breeze for users to sign-up and become members of your website. The plugin allows you to add beautiful user profiles to your site and is designed for creating advanced online communities and membership sites. Lightweight and highly extendible, Ultimate Member will enable you to create almost any type of site where users can join and become members with absolute ease.
مميزات الإضافة تتضمن:
- واجهة الملفات الشخصية للمستخدمين
- واجهة (Front-end) التسجيل للمستخدمين
- واجهة (Front-end) تسجيل الدخول للمستخدمين
- حقول نموذج مخصصة
- منطق شرطي لحقول النموذج
- مؤلف النموذج بالسحب والإدراج
- صفحة حساب المستخدم
- أدوار ورُتب مخصصة للمستخدم
- أدلة الأعضاء
- البريد الإلكتروني للمستخدم
- تقييد المحتوى
- قوائم التنقل الشرطية
- عرض مشاركات ومقالات الكاتب وتعليقاته على ملفات تعريف المستخدمين
- سهولة التعامل للمطورين مع العشرات من الإجراءات والفلاتر
إقرأ عن جميع مميزات الإضافة على Ultimate Member
الملحقات المدفوعة
Ultimate Member has a range of extensions that allow you to extend the power of the plugin. You can purchase all of these extensions at a significant discount with one of our paid plans or you can purchase extensions individually.
- Zapier – Allow to integrate the Zapier popular apps with Ultimate Member
- Stripe – Sell paid memberships to access your website via Stripe subscriptions
- إضافة ملاحظات المستخدم (User Notes) السماح للمستخدمين بإنشاء ملاحظات عامة وخاصة من ملفهم الشخصي
- إضافة تبويبات الملف الشخصي (Profile Tabs) السماح بإضافة علامات التبويب المخصصة إلى الملفات الشخصية
- إضافة (مواقع المستخدم) User Locations – السماح لعرض المستخدمين على خريطة بصفحة دليل الأعضاء، والسماح للمستخدمين بإضافة مواقعهم عبر ملفاتهم الشخصية
- إضافة Unsplash السماح للمستخدمين بتحديد صورة غلاف ملف التعريف من Unsplash لملفاتهم الشخصية
- إضافة (العلامات المرجعية) User Bookmarks – السماح للمستخدمين بوضع إشارات أو علامات مرجعية لمحتوى من موقعك
- إضافة (صور المستخدم) User Photos – السماح للمستخدمين برفع الصور إلى ملفهم الشخصي
- إضافة (المجموعات) Groups – تسمح للمستخدمين بإنشاء مجموعات والانضمام إليها حول المواضيع والاهتمامات المشتركة، إلخ.
- إضافة (المحتوى الخاص) Private Content – لعرض محتوى خاص للمستخدمين المسجلين دخولهم الذين يمكنهم الوصول إليه فقط
- إضافة (وسوم المستخدم) User Tags – يتيح لك إضافة نظام وسوم للمستخدم إلى موقع الويب الخاص بك
- إضافة (النشاط الاجتماعي) Social Activity – السماح للمستخدمين بإنشاء منشورات عامة على الحائط، ومشاهدة نشاط المستخدمين الآخرين
- إضافة (ووكومرس) WooCommerce – تسمح لك بدمج WooCommerce مع Ultimate Member
- إضافة (الرسائل الخاصة) Private Messages – أضف نظام للمراسلة الخاصة إلى موقعك واسمح للمستخدمين بإرسال رسائل إلى بعضهم البعض
- إضافة (المتابعين) Followers – السماح للمستخدمين بمتابعة بعضهم البعض على موقعك وحماية معلومات ملفاتهم الشخصية
- إضافة (نظام الإشعارات الوقت الفعلي) Real-time Notifications – أضف نظام إشعارات إلى موقعك حتى يتمكن المستخدمون من تلقّي إشعارات في الوقت الفعلي
- إضافة (تسجيل الدخول بواسطة المواقع الاجتماعية) Social Login – السماح للمستخدمين بالتسجيل، وتسجيل الدخول إلى موقعك عبر Facebook و Twitter و G+ و LinkedIn و Instagram و Vkontakte ؛ (VK.com)
- إضافة bbPress – مع الإضافة الملحقة bbPress، يمكنك دمج Ultimate Member مع إضافة bbPress الرسمية
- إضافة MailChimp – السماح للمستخدمين بالاشتراك في قوائم MailChimp الخاصة بك أثناء التسجيل على موقعك ومزامنة بيانات المستخدم (User meta) مع MailChimp
- إضافة (مراجعات المستخدم) User Reviews – السماح للمستخدمين بتقييم ومراجعة بعضهم البعض باستخدام نظام تقييم / مراجعة من 5 نجوم
- إضافة (المستخدمون الموثَّقون) Verified Users – إضافة نظام التحقَّق من المستخدم على موقعك حتى يمكن التحقق من حسابات المستخدمين
- إضافة (إدارة واكتساب النقاط والشارات) myCRED – باستخدام الإضافة الملحقة myCRED يمكنك دمج Ultimate Member مع إضافة إدارة النقاط myCRED الشهيرة
- إضافة (الملاحظات والتنبيهات) Notices – تنويه المستخدمين إلى المعلومات المهمة باستخدام الإشعارات الشرطية
- إضافة (استكمال معلومات الملف الشخصي) Profile Completeness – تشجيع أو إجبار المستخدمين على إكمال ملفاتهم الشخصية مع الإضافة الملحقة Profile Completeness
- إضافة (الأصدقاء) Friends – السماح للمستخدمين بأن يصبحوا أصدقاء من خلال إرسال / قبول / رفض طلبات الصداقة
الملحقات المجانية
- إضافة JobsBoardWP الملحقة – هذه الإضافة المجانية تقوم بدمج Ultimate Member مع إضافة job board عبر مستودع الإضافات JobBoardWP.
- إضافة ForumWP الملحقة – هذه الإضافة المجانية تقوم بدمج Ultimate Member مع إضافة ForumWP.
- إضافة Terms & Conditions تضيف خانة وحقل تحديد الشروط والأحكام إلى نماذج التسجيل الخاصة بك وتطلب من المستخدمين الموافقة على الشروط والأحكام الخاصة بك قبل التسجيل على موقعك.
- إضافة Google reCAPTCHA إيقاف الـ Bots عبر نماذج التسجيل، ونماذج تسجيل الدخول باستخدام Google reCAPTCHA.
- إضافة Online Users – تعرض المستخدمين المتصلين أون لاين مع هذه الإضافة الملحقة
القالب
Our official theme is purpose built for websites that have logged in and out users. The theme has deep integration with Ultimate Member plugin and the extensions, different header designs for logged-in/out users and works alongside the Beaver Builder and Elementor page builders.
إضافاتنا الأخرى
بالإضافة إلى Ultimate Member، لدينا أيضًا إضافتان برمجية: إضافة ForumWP و إضافة JobBoardWP – لوحة الوظائف.
إضافة FORUMWP
إضافة FORUMWP is a forum plugin which adds an online forum to your website, allowing users to create topics and write replies. Forums are a great way to build and grow an online community.
إضافة JobBoardWP – لوحة الوظائف
إضافة JobBoardWP – لوحة الوظائف is a job board plugin which adds a modern job board to your website. Display job listings and allow employers to submit and manage jobs all from the front-end.
التطوير * الترجمة
If you’re a developer and would like to contribute to the source code of the plugin you can do so via our GitHub Repository.
هل تريد إضافة لغة جديدة إلى Ultimate Member؟ عظيم! يمكنك المساهمة عبر translate.wordpress.org.
If you are a developer and you need to know the list of UM Hooks, make this via our Hooks Documentation or Hooks Documentation v2.
If you are a developer and you need to know the structure of our code, make this via our Documentation API.
الوثائق والدعم الفني
Got a problem or need help with Ultimate Member? Head over to our documentation and perform a search of the knowledge base. If you can’t find a solution to your issue then you can create a topic on the support forum.
لقطات الشاشة
المكوّنات
تقدّم هذه الإضافة 4 مكوّنات.
- Account Displaying the account page of the current user
- Form Choose display form
- Member Directory Choose display directory
- Password Reset Displaying the password reset form
التنصيب
- تفعيل الإضافة
- هذا كل شي، انتقل إلى Ultimate Member > الإعدادات لتخصيص خيارات الإضافة
- لمزيد من التفاصيل، يرجى زيارة صفحة الوثائق الرسمية.
الأسئلة المتكررّة
-
Do I need to know any coding to use this plugin?
-
No, we have built Ultimate Member to be extremely easy to use and does not require you to manually build shortcodes or have any coding knowledge.
-
Is Ultimate Member mobile responsive?
-
Yes. Ultimate Member is designed to adapt nicely to any screen resolution. It includes specific designs for phones, tablets and desktops.
-
Is Ultimate Member multi-site compatible?
-
Yes. Ultimate Member works great on both single site and multi-site WordPress installs.
-
Does the plugin work with any WordPress theme?
-
Yes. Ultimate Member will work with any properly coded theme. However, some themes may cause conflicts with the plugin. If you find a styling issue with your theme please create a post in the community forum.
-
Does the plugin work with caching plugins?
-
The plugin works with popular caching plugins by automatically excluding Ultimate Member pages from being cached. This ensures other visitors to a page will not see the private information of another user. However, if you add features of Ultimate Member to other pages you have to exclude those pages from being cached through your cache plugin settings panel.
-
Does Ultimate Member restrict access to wp-login.php when the plugin is active?
-
The plugin does not restrict access to the wp-login.php page when active, so that our plugin does not interfere with the existing functionality of a website or other plugins that may utilise the default login page. If you wish to restrict access to the wp-login.php page you can use a plugin such as WPS Hide Login or another plugin that removes the ability to login via wp-login.php.
-
Are Ultimate Member Login/Registration pages required?
-
No, you do not need to use our plugin’s login or registration pages and can use another plugin or the default WordPress methods for user registration and login.
-
Are additional PHP modules necessary for the plugin to work correctly?
-
No specific extensions are needed. But we highly recommended keep active these PHP modules:
mbstring,json,dom,exif,gd,fileinfo,curl,iconv. wp-admin > Tools > Site Health page has a summary about your installation and required modules. All major extensions are listed here.
المراجعات
المساهمون والمطوّرون
“Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin” هو برنامج مفتوح المصدر. وقد ساهم هؤلاء الأشخاص بالأسفل في هذه الإضافة.
المساهمونلقد تم ترجمة ”Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin“ إلى 30 لغة. شكراً إلى جميع المُترجمين لمُساهماتهم.
مُهتم بالتطوير؟
تصفّح الشفرة، تحقق من مستودع SVN، أو الاشتراك في سجل التطوير بواسطة RSS.
سجل التغييرات
Important:
IMPORTANT: PLEASE UPDATE THE PLUGIN TO AT LEAST VERSION 2.6.7 IMMEDIATELY. VERSION 2.6.7 PATCHES SECURITY PRIVILEGE ESCALATION VULNERABILITY. PLEASE SEE THIS ARTICLE FOR MORE INFORMATION
2.14.0 2026-09-29
Enhancements
- Added:
$form_idparameter to the action hooksum_before_form,um_before_{$mode}_fields,um_main_{$mode}_fields,um_after_form_fields,um_after_{$mode}_fieldsandum_after_form. - Added: Action hook
um_before_render_dynamic_modal_contentfor 3rd-party integration when the admin popup is opened. - Added: Filter hooks
um_email_validation_real_error_codesandum_email_validation_error_messagefor 3rd-party integration to change or make visible the real error message for email fields validation. - Added: Threads field support in the UM Forms and Social Icons meta-row.
Bugfixes
- Fixed: Security issue related to an unauthenticated PHP Object Injection vulnerability. (Reported by Ananda Dhakal (Patchstack)). Added
um_maybe_unserialize()function. - Fixed: Security issue related to administrator Stored SQL Injection via Directory Search-Field Identifiers. (Reported by Ananda Dhakal (Patchstack)). Added sanitizing for the searching fields in the member directory.
- Fixed: Security issue related to an unauthenticated Improper Enforcement of Behavioral Workflow vulnerability. (Reported by Ananda Dhakal (Patchstack)). Added unique nonce fields and attributes for requests.
- Fixed: CVE-2026-96270 security issue. Added sanitizing for the form_id attribute during the Ultimate Member forms submission. (Reported by Wordfence).
- Fixed: CVE-2026-93428 security issue. Fixed fields privacy when displaying the User Profile fields. (Reported by Wordfence).
- Fixed: Security issue related to Privilege Escalation. Fixed user account submission and nonce security. Reset the user if it hasn’t the ability to download the file. (Reported by Intrudify (Patchstack)).
- Fixed:
is_url()validation for the social links fields. - Fixed:
unique_emailvalidation. Parse primary and secondary email fields to make the email unique between them.
Templates Requiring Update
- profile/comments.php
- profile/posts.php
- login.php
- members.php
- profile.php
- register.php
Deprecated
- Deprecated:
UM()->check_ajax_nonceandUM()->admin()->check_ajax_nonce()functions. Use WordPress nativewp_verify_nonce(),check_admin_referer()andcheck_ajax_referer()instead with unique nonce field values. Left them now for backward compatibility. - Deprecated: Using
um_admin_scripts.nonceandum_scripts.noncelocalized data in UM scripts. Left them still localized for backward compatibility. - Deprecated: JS common action for
'.um-ajax-action'class. It’s not used anymore in UM core and extensions and can be removed the same as AJAX handler forum_muted_action. - Deprecated: Action hook
um_run_ajax_function__{$hook}used in theum_muted_actionhandler. - Marked as deprecate soon:
in_groupattribute for the fields in the UM Forms builder.
Note: Cached and optimized/minified assets(JS/CSS) must be flushed/re-generated after the upgrade
2.13.1 2026-09-15
Enhancements
- Added: Fallback for
wp-cli/wp-config-transformerlibrary if the wp-config.php file isn’t writable. - Added: Filter hook
um_members_directory_filter_text3rd parameter$is_defaultto check if it’s admin filtering or frontend query. - Added: ‘Administrative capabilities ban’ option enabled by default after the first installation.
- Optimized: Slow SQL query for batch empty account status check.
- Optimized: Redundant SQL calls when editing the Profile page with callback dropdowns. Cached usermeta existence checks per user and key during a single load (Reported by @MissVeronica, author @faisalahammad).
Bugfixes
- Fixed: Security issue related to an unauthenticated visitor can store JavaScript that runs in an administrator’s session, through their own profile name. (Reported by Karthik Ramakrishnan and WPScan team). Fixed
um_convert_tags()function and applied the escapers throughout the placeholder replacement. - Fixed: Using LIKE compare for the text-type filters with custom usermeta table (Reported by @MissVeronica, author @faisalahammad).
- Fixed: “Can user edit this field?” field setting displaying only for the User Profile form fields.
- Fixed: Getting the pages list in the wp-admin UM > Settings > General > Pages section.
- Fixed: Displaying the field-type time on the User Profile page.
- Fixed: Using
illegal_user_loginsfor the current admin user with the username specified in the illegal user logins list.
Deprecated
- Deprecated: Filter hook
um_members_directory_filter_text_meta_valueis fully deprecated, replacement isn’t required for the text-type filter field.
2.13.0 2026-08-24
Enhancements
- Added: Using
illegal_user_loginsfilter to sanitize theuser_loginfield value during registration or upgrade. - Added: Using
wp-cli/wp-config-transformerlibrary to set Ultimate Member > API keys settings constants in wp-config.php instead of storing them in DB. - Added: New user-capabilities functions
UM()->common()->users()->can_view_user(),UM()->common()->users()->get_privacy_setting(),UM()->common()->users()->is_user_profile_private(),UM()->common()->users()->get_restricted_privacy_notice(),UM()->common()->users()->can_view_private_user_profile(),UM()->common()->users()->can_view_user_profile(). The future replacement for theum_can_view_profile()helper with different cases to check. - Updated: Version of the WordPress native excluded functions to avoid the using them in the callbacks.
Bugfixes
- Fixed:
WP_Filesystem()initialization optimization. InitWP_Filesystem()only once when it’s necessary. - Fixed: Redirect on non-main queries (breaks Spectra and block themes). Added conditional check for the main query (based on @faisalahammad suggestions).
- Fixed: Registration form infinite loop – gdpr-register.php calls
the_contentrecursively causing PHP fatal error. Excluded predefined UM pages and pages with [ultimatemember] shortcode from the list, render empty content for such pages if they are already selected to avoid PHP error (based on @faisalahammad suggestions). - Fixed: Causes site-wide
rest_cookie_invalid_nonceon all authenticated REST requests. Refactored admin notice handling to enhance security and flexibility. Removed using localizedum_admin_scripts.nonceglobally on wp-admin. It’s localized only on UM wp-admin pages. (based on @michaeldavisdcpersonal report and @faisalahammad suggestions). - Fixed: Security issue when an unauthenticated visitor can read the content of comments awaiting moderation. (Reported by Alessandro Greco (Aleff) and Giovambattista Ianni, University of Calabria (UNICAL)).
- Fixed: Security issue related to an unauthenticated privilege escalation through the profile form role field. (Reported by Jakub Herman).
- Fixed: Security issue, CVE ID: CVE-2026-18547. Used ‘user_input’ allowed a tag list to sanitize HTML-enabled textarea fields. Deprecated Pickadate.JS and Pickatime.JS libraries for User Forms fields.
- Fixed: Member Directory type-button styles.
- Fixed: Added fallback for the date and time fields to show date and time using the WordPress native format.
Templates Requiring Update
- gdpr-register.php
- profile.php
Deprecated
- Deprecated: Pickadate.JS and Pickatime.JS libraries for User Forms fields. Used HTML native
<input type="date" />and<input type="time" />instead.
Note: Cached and optimized/minified assets(JS/CSS) must be flushed/re-generated after the upgrade












