UserPro - Community and User Profile WordPress Plugin

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.10

    Open

    The UserPro plugin for WordPress, which allows users to create profiles and connect with others in a community, has a security issue. This issue, known as Directory Traversal, affects all versions up...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.9

    Open

    The Userpro plugin for WordPress has a security issue that allows hackers to access sensitive information from the database. This is because the plugin did not properly protect against SQL Injection,...

    Read More
  • Access violation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.9

    Open

    The Userpro plugin for WordPress has a security issue that allows unauthorized changes to be made to data. This is because it lacks a feature that checks for proper permission. This means that attack...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.9

    Open

    The Userpro plugin for WordPress has a security issue called Local File Inclusion, which affects versions up to 5.1.9. This allows unauthorized individuals to add and run any files on the server, whi...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.9

    Open

    The Userpro plugin for WordPress has a security issue that could allow hackers to inject malicious code into web pages. This could happen if a user clicks on a link that tricks them into taking an ac...

    Read More
  • Authentication vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.8

    Fixed

    The UserPro plugin for WordPress has a security flaw that allows hackers to take over user accounts without needing to log in. This puts websites at risk of unauthorized access by these attackers.

    Read More
  • Weak configuration vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.6

    Fixed

    The UserPro plugin for WordPress has a security flaw that allows unauthorized users to create accounts, even if the administrator has disabled registration. This vulnerability exists in all versions ...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.5

    Fixed

    The UserPro plugin for WordPress has a security issue called Stored Cross-Site Scripting. This happens when someone uses the 'userpro' feature and doesn't properly clean up the information they put i...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.0

    Fixed

    The UserPro plugin for WordPress, up to and including version 5.1.0, is vulnerable to an attack called Cross-Site Request Forgery. This means that unauthenticated attackers may be able to trick a sit...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.1

    Fixed

    The UserPro plugin for WordPress has a security issue that affects versions up to, and including, 5.1.1. This vulnerability is related to Cross-Site Request Forgery, which is when attackers can bypas...

    Read More
  • Access violation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.4

    Fixed

    The UserPro plugin for WordPress is not secure in versions up to 5.1.4. This means that people who have signed in with limited permissions, such as a subscriber, may be able to change their user role...

    Read More
  • Authentication vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.1

    Fixed

    The UserPro plugin for WordPress is not secure in versions up to and including 5.1.1. This is because it does not have enough checks in place when resetting passwords. The function used for resetting...

    Read More
  • Authentication vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.1

    Fixed

    The UserPro plugin for WordPress is vulnerable to a security issue in versions up to, and including, 5.1.1. This means that people who are not normally allowed to log in, can gain access to the site ...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.0

    Fixed

    The UserPro plugin for WordPress is not secure in versions up to 5.1.0. This means attackers can cause harm to the website without needing to authenticate themselves. This is possible because the plu...

    Read More
  • Access violation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.4

    Fixed

    The UserPro plugin for WordPress is vulnerable to unauthorized access of data. This means that people who should not have access can get access to sensitive information. In versions up to and includi...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.1

    Fixed

    The UserPro plugin for WordPress, up to version 5.1.1, has a security vulnerability that can be exploited by unauthenticated attackers. If they can get a site administrator to do something like click...

    Read More
  • Access violation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.1

    Fixed

    The UserPro plugin for WordPress has a security vulnerability that could make it possible for someone outside the website to access, change, or delete information without permission. This is an issue...

    Read More
  • Access violation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.1

    Fixed

    The UserPro plugin for WordPress is vulnerable to a security issue. Attackers with certain permissions can access private user information, which can be used to gain access to higher privileged accou...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 5.1.1

    Fixed

    The UserPro plugin for WordPress, up to version 5.1.1, is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability is caused by the 'export_users' function not properly va...

    Read More
  • Access violation vulnerability in UserPro - Community and User Profile WordPress Plugin 4.9.21

    Fixed

    The UserPro plugin for WordPress is an application that allows people to register and access certain content on a website. Unfortunately, versions of the plugin up to and including 4.9.20 have a secu...

    Read More
  • Access violation vulnerability in UserPro - Community and User Profile WordPress Plugin 4.9.28

    Fixed

    The UserPro plugin for WordPress has a security vulnerability in versions 4.9.27 and earlier. This means that someone could register for an account on a WordPress site using the plugin and be given a...

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 4.9.34

    Fixed

    The Instagram-PHP-API

    Read More
  • Input validation vulnerability in UserPro - Community and User Profile WordPress Plugin 4.9.23

    Fixed

    The UserPro plugin for WordPress

    Read More
  • Authentication vulnerability in UserPro - Community and User Profile WordPress Plugin 4.9.17.1

    Fixed

    The UserPro plugin for WordPress

    Read More