Input validation vulnerability in UserPro – Community and User Profile WordPress Plugin 5.1.0

The UserPro plugin for WordPress is not secure in versions up to 5.1.0. This means attackers can cause harm to the website without needing to authenticate themselves. This is possible because the plugin does not have the correct measures in place to prevent malicious requests. If a website administrator clicks on a link created by an attacker, the attacker can update user information and add malicious JavaScript.

Detected in:

UserPro - Community and User Profile WordPress Plugin open vulnerable versions: >= * <= 5.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.