CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Update
Media Manager for UserPro <= 3.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerability
UserPro <= 5.1.6 - Disabled Membership Registration Bypass
The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insuff…
UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection
UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions
UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation
UserPro <= 5.1.1 - Insecure Password Reset Mechanism
UserPro <= 5.1.1 - Authentication Bypass to Administrator
UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata
UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template
UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation
UserPro <= 5.1.1 - Missing Authorization via multiple functions
UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode
UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposure
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_de…
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain ad…
Showing 1 to 19 CVEs · page 1