Record summary

CVE-2017-16562 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 5, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Userpro < 4.9.17.1 - Authentication BypassExploitDB exploitby Colette ChamberlandNot analyzed1 file
ExploitDB

PoC details

References

4