VendorsUserpropluginuserproany version
Vulnerabilities

Userproplugin UserPRO any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2017-16562
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.
Published 2017-11-09 · Modified
9.81 PoCEPSS 0.274
CVE-2023-2437
UserPro <= 5.1.1 - Authentication Bypass to Administrator
Published 2023-11-22 · Modified
9.8EPSS 0.067
CVE-2023-2449
UserPro <= 5.1.1 - Insecure Password Reset Mechanism
Published 2023-11-22 · Modified
9.8EPSS 0.009
CVE-2024-35700
WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerability
Published 2024-06-04 · Modified
9.8EPSS 0.005
CVE-2023-6009
UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation
Published 2023-11-22 · Modified
8.8EPSS 0.009
CVE-2023-2440
UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation
Published 2023-11-22 · Modified
8.8EPSS 0.003
CVE-2023-2497
UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection
Published 2023-11-22 · Modified
8.8EPSS 0.003
CVE-2023-6007
UserPro <= 5.1.1 - Missing Authorization via multiple functions
Published 2023-11-22 · Modified
7.3EPSS 0.003
CVE-2023-2448
UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template
Published 2023-11-22 · Modified
6.5EPSS 0.010
CVE-2023-2446
UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode
Published 2023-11-22 · Modified
6.5EPSS 0.008
CVE-2023-2439
The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published 2024-01-31 · Modified
6.4EPSS 0.003
CVE-2023-6008
UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions
Published 2023-11-22 · Modified
6.3EPSS 0.002
CVE-2018-16285
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
Published 2018-09-06 · Modified
6.1EPSS 0.013
CVE-2023-2447
UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposure
Published 2023-11-22 · Modified
6.1EPSS 0.002
CVE-2023-2438
UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata
Published 2023-11-22 · Modified
6.1EPSS 0.002
CVE-2024-0701
UserPro <= 5.1.6 - Disabled Membership Registration Bypass
Published 2024-02-05 · Modified
5.3EPSS 0.006