Userproplugin / Userpro
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-35700 | WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerability | CRITICAL | 9.8 | Jun 4, 2024 |
| CVE-2024-0701 | UserPro <= 5.1.6 - Disabled Membership Registration Bypass | MEDIUM | 5.3 | Feb 5, 2024 |
| CVE-2023-2439 | The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insuff… | MEDIUM | 6.4 | Jan 31, 2024 |
| CVE-2023-2497 | UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection | HIGH | 8.8 | Nov 22, 2023 |
| CVE-2023-6008 | UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions | MEDIUM | 6.3 | Nov 22, 2023 |
| CVE-2023-6009 | UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation | HIGH | 8.8 | Nov 22, 2023 |
| CVE-2023-2449 | UserPro <= 5.1.1 - Insecure Password Reset Mechanism | CRITICAL | 9.8 | Nov 22, 2023 |
| CVE-2023-2437 | UserPro <= 5.1.1 - Authentication Bypass to Administrator | CRITICAL | 9.8 | Nov 22, 2023 |
| CVE-2023-2438 | UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata | MEDIUM | 6.1 | Nov 22, 2023 |
| CVE-2023-2448 | UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template | MEDIUM | 6.5 | Nov 22, 2023 |
| CVE-2023-2440 | UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation | HIGH | 8.8 | Nov 22, 2023 |
| CVE-2023-6007 | UserPro <= 5.1.1 - Missing Authorization via multiple functions | HIGH | 7.3 | Nov 22, 2023 |
| CVE-2023-2446 | UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode | MEDIUM | 6.5 | Nov 22, 2023 |
| CVE-2023-2447 | UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposure | MEDIUM | 6.1 | Nov 22, 2023 |
| CVE-2018-16285 | The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php. | MEDIUM | 6.1 | Sep 6, 2018 |
| CVE-2017-16562 | The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain ad… | CRITICAL | 9.8 | Nov 9, 2017 |
Showing 1 to 16 of 16 CVEs