Access violation vulnerability in User registration & user profile – UserPlus 2.0

The UserPlus plugin for WordPress has a security issue that allows unauthorized changes to be made to data. This is because the ‘save_metabox_form’ function does not properly check for the right permissions. This means that someone with editor or higher permissions can change the registration form role to administrator, giving them more control and power.

Detected in:

User registration & user profile – UserPlus open vulnerable versions: >= * <= 2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.