Input validation vulnerability in UserPro – Community and User Profile WordPress Plugin 5.1.1

The UserPro plugin for WordPress has a security issue that affects versions up to, and including, 5.1.1. This vulnerability is related to Cross-Site Request Forgery, which is when attackers can bypass authentication and add, modify, or delete user meta and plugin options. The issue is caused by incorrect or missing validation of nonce functions.

Detected in:

UserPro - Community and User Profile WordPress Plugin open vulnerable versions: >= * <= 5.1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.