codecanyon.netConfirmation
https://codecanyon.net/item/userpro-user-profiles-with-social-login/5958681?s_rank=9 CVE-2017-16562
CRITICAL
userproplugin userpro Improper Authentication
Record summary
CVE-2017-16562 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 5, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Userpro < 4.9.17.1 - Authentication BypassExploitDB exploitby Colette ChamberlandNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-16562 wpvulndb.com
https://wpvulndb.com/vulnerabilities/8950 43117exploit
https://www.exploit-db.com/exploits/43117