Access violation vulnerability in UserPro – Community and User Profile WordPress Plugin 4.9.21

The UserPro plugin for WordPress is an application that allows people to register and access certain content on a website. Unfortunately, versions of the plugin up to and including 4.9.20 have a security issue that allows attackers to create users with the highest level of access to the website, known as an “administrator” role. This means that attackers can use the administrator role to run code on the website, which can cause serious problems. To avoid this issue, make sure you are using the most recent version of the UserPro plugin.

Detected in:

UserPro - Community and User Profile WordPress Plugin open vulnerable versions: >= * < 4.9.21

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.