Access violation vulnerability in UserPro – Community and User Profile WordPress Plugin 5.1.4

The UserPro plugin for WordPress is not secure in versions up to 5.1.4. This means that people who have signed in with limited permissions, such as a subscriber, may be able to change their user role. This is done by providing the ‘wp_capabilities’ parameter when updating their profile.

Detected in:

UserPro - Community and User Profile WordPress Plugin open vulnerable versions: >= * <= 5.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.