CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2024-12822 CRITICAL

Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Update

CVSS 9.8 EPSS 0.58% Jan 30, 2025
CVE-2024-12821 HIGH

Media Manager for UserPro <= 3.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

CVSS 8.8 EPSS 0.36% Jan 30, 2025
CVE-2024-35700 CRITICAL

WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerability

CVSS 9.8 EPSS 0.49% Jun 4, 2024
CVE-2024-0701 MEDIUM

UserPro <= 5.1.6 - Disabled Membership Registration Bypass

CVSS 5.3 EPSS 0.58% Feb 5, 2024
CVE-2023-2439 MEDIUM

The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insuff…

CVSS 6.4 EPSS 0.33% Jan 31, 2024
CVE-2023-2497 HIGH

UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection

CVSS 8.8 EPSS 0.27% Nov 22, 2023
CVE-2023-6008 MEDIUM

UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions

CVSS 6.3 EPSS 0.18% Nov 22, 2023
CVE-2023-6009 HIGH

UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation

CVSS 8.8 EPSS 0.92% Nov 22, 2023
CVE-2023-2449 CRITICAL

UserPro <= 5.1.1 - Insecure Password Reset Mechanism

CVSS 9.8 EPSS 0.89% Nov 22, 2023
CVE-2023-2437 CRITICAL

UserPro <= 5.1.1 - Authentication Bypass to Administrator

CVSS 9.8 EPSS 6.75% Nov 22, 2023
CVE-2023-2438 MEDIUM

UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata

CVSS 6.1 EPSS 0.16% Nov 22, 2023
CVE-2023-2448 MEDIUM

UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template

CVSS 6.5 EPSS 0.96% Nov 22, 2023
CVE-2023-2440 HIGH

UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation

CVSS 8.8 EPSS 0.27% Nov 22, 2023
CVE-2023-6007 HIGH

UserPro <= 5.1.1 - Missing Authorization via multiple functions

CVSS 7.3 EPSS 0.35% Nov 22, 2023
CVE-2023-2446 MEDIUM

UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode

CVSS 6.5 EPSS 0.84% Nov 22, 2023
CVE-2023-2447 MEDIUM

UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposure

CVSS 6.1 EPSS 0.18% Nov 22, 2023
CVE-2019-14470 MEDIUM

cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_de…

CVSS 6.1 EPSS 82.96% Sep 4, 2019
CVE-2018-16285 MEDIUM

The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.

CVSS 6.1 EPSS 1.34% Sep 6, 2018
CVE-2017-16562 CRITICAL

The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain ad…

CVSS 9.8 EPSS 27.37% Nov 9, 2017

Showing 1 to 19 CVEs · page 1