Userproplugin

Userpro

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 04.06.2024 14:15:14
  • Zuletzt bearbeitet 21.11.2024 09:20:41

Improper Privilege Management vulnerability in DeluxeThemes Userpro allows Privilege Escalation.This issue affects Userpro: from n/a through 5.1.8.

  • EPSS 0.18%
  • Veröffentlicht 05.02.2024 22:16:04
  • Zuletzt bearbeitet 21.11.2024 08:47:10

The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use of client-side restrictions to enforce the 'Disabled registration' Membership feature within the plugin's Ge...

  • EPSS 0.08%
  • Veröffentlicht 31.01.2024 03:15:07
  • Zuletzt bearbeitet 21.11.2024 07:58:37

The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po...

  • EPSS 0.23%
  • Veröffentlicht 22.11.2023 16:15:15
  • Zuletzt bearbeitet 21.11.2024 08:42:58

The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.1.1. This makes it possible for unauthen...

  • EPSS 0.07%
  • Veröffentlicht 22.11.2023 16:15:15
  • Zuletzt bearbeitet 21.11.2024 08:42:58

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to ...

  • EPSS 0.15%
  • Veröffentlicht 22.11.2023 16:15:15
  • Zuletzt bearbeitet 21.11.2024 08:42:58

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with min...

Exploit
  • EPSS 73.46%
  • Veröffentlicht 22.11.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:58:37

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible fo...

  • EPSS 0.15%
  • Veröffentlicht 22.11.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:58:37

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'userpro_save_userdata' function. This makes it possible for unauthentic...

  • EPSS 0.09%
  • Veröffentlicht 22.11.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:58:37

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing nonce validation in the 'admin_page', 'userpro_verify_user' and 'verifyUnverifyAllUsers' functions. This make...

  • EPSS 0.41%
  • Veröffentlicht 22.11.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:58:38

The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' function in versions up to, and including, 5.1.4. This makes it possible for unauthenticated attackers...