Authentication vulnerability in UserPro – Community and User Profile WordPress Plugin 5.1.1

The UserPro plugin for WordPress is vulnerable to a security issue in versions up to, and including, 5.1.1. This means that people who are not normally allowed to log in, can gain access to the site if they have the email address of an existing user. An attacker can use two special codes, called CVE-2023-2448 and CVE-2023-2446, to get the email address of a user and then exploit this vulnerability.

Detected in:

UserPro - Community and User Profile WordPress Plugin open vulnerable versions: >= * <= 5.1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.