Input validation vulnerability in userpro-messaging 4.10.0

A popular plugin for WordPress called “Private Messages for UserPro” has a security issue in versions up to 4.10.0. This vulnerability allows people without proper authorization to access and run any files on the server, potentially causing harm. It could also be used to get confidential information or execute malicious code, even if the files are typically considered safe, like images.

Detected in:

Private Messages for UserPro open vulnerable versions: >= * <= 4.10.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.