Security researchers have found that the Ultimate Member WordPress plugin is found to have critical vulnerabilities and should be disabled ASAP as developers work out a patch.
If you are a BYTE website support customer you will be contacted to discuss remediation plan options.
More details can be found here:
https://www.bleepingcomputer.com/news/security/hackers-exploit-zero-day-in-ultimate-member-wordpress-plugin-with-200k-installs/