Access violation vulnerability in UserPro – Community and User Profile WordPress Plugin 5.1.4

The UserPro plugin for WordPress is vulnerable to unauthorized access of data. This means that people who should not have access can get access to sensitive information. In versions up to and including version 5.1.4 of the plugin, an attacker can use a security vulnerability (named CVE-2023-2446) to get this sensitive information. This is because of a missing capability check on the ‘userpro_shortcode_template’ function.

Detected in:

UserPro - Community and User Profile WordPress Plugin open vulnerable versions: >= * <= 5.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.