Showing 4 vulnerabilities on this page for userpro

Signals CISA KEV Ransomware Nuclei
userproplugin vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerability

Incorrect Privilege Assignment vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.8.

CWE-266CWE-269Jun 4, 2024
CVSS9.8v3.1EPSS0.487%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

UserPro <= 5.1.1 - Authentication Bypass to Administrator

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email. An attacker can leverage CVE-2023-2448 and CVE-2023-2446 to get the user's email address to successfully exploit this

CWE-287CWE-288Nov 22, 20231 related artifact
CVSS9.8v3.1EPSS6.8%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode

The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account.

CWE-200Nov 22, 2023
CVSS6.5v3.1EPSS0.849%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

userproplugin userpro Improper Authentication

The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.

CWE-287Nov 9, 2017
CVSS9.8v3.0EPSS27.4%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX