CVE-2023-2449
- EPSS 0.48%
- Veröffentlicht 22.11.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:58:38
The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (u...
CVE-2023-2497
- EPSS 0.14%
- Veröffentlicht 22.11.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:58:43
The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'import_settings' function. This makes it possible for unauthenticated a...
CVE-2023-2446
- EPSS 0.24%
- Veröffentlicht 22.11.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 07:58:37
The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1. This is due to insufficient restriction on sensitive user meta values that can be called via that s...
CVE-2023-2447
- EPSS 0.23%
- Veröffentlicht 22.11.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 07:58:38
The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the 'export_users' function. This makes it possible for unauthenticated atta...
CVE-2018-16285
- EPSS 1.63%
- Veröffentlicht 06.09.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:27
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
CVE-2017-16562
- EPSS 48.17%
- Veröffentlicht 10.11.2017 02:29:18
- Zuletzt bearbeitet 20.04.2025 01:37:25
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to...