Input validation vulnerability in UserPro – Community and User Profile WordPress Plugin 5.1.1

The UserPro plugin for WordPress, up to version 5.1.1, has a security vulnerability that can be exploited by unauthenticated attackers. If they can get a site administrator to do something like click on a link, they can use a special request to modify the role of verified users and give them the same privileges as any user, such as an Administrator. This is possible because of the lack of validation in the ‘admin_page’, ‘userpro_verify_user’ and ‘verifyUnverifyAllUsers’ functions.

Detected in:

UserPro - Community and User Profile WordPress Plugin open vulnerable versions: >= * <= 5.1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.