He used console to add himself as superadmin, what makes this a ulx hack?
Ulx makes it easier for people to add themselves if they have console access (intended or not), but by all means, if someone you don't want has console access, you've got more problems than what ULX can help with.
Do you store your rcon password in your cfg files?
If so, there are many known exploits for reading a server's cfg files.
Please understand, by no means am I, or we (speaking for my team) saying with 100% absolute certainty that ULX isn't exploitable, but we are saying with confidence that your issue is likely not directly due to ULX.
ULX - we make things easier for administration, even for people you don't intend to (when they have console/r00t access)