userproplugin kayıtları
userproplugin üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %5,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-862 Missing Authorization4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-266 Incorrect Privilege Assignment2
- CWE-287 Improper Authentication1
- CWE-620 Unverified Password Change1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2019-14470Kavram kanıtı | cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/sinstagram-php-api project · instagram-php-api · CWE-79 | Orta6,1 | — | %83,0 | 4 Eyl 2019 |
47Planlayın | CVE-2017-16562Kavram kanıtı | The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authenticuserproplugin · userpro · CWE-287 | Kritik9,8 | — | %27,4 | 9 Kas 2017 |
39İzleyin | CVE-2023-2449İstismar yok | UserPro <= 5.1.1 - Insecure Password Reset Mechanismuserproplugin · userpro · CWE-620 | Kritik9,8 | — | %0,9 | 22 Kas 2023 |
39İzleyin | CVE-2024-12822İstismar yok | Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Updateuserproplugin · media manager · CWE-862 | Kritik9,8 | — | %0,6 | 30 Oca 2025 |
39İzleyin | CVE-2024-35700İstismar yok | WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerabilityuserproplugin · userpro · CWE-266 | Kritik9,8 | — | %0,5 | 4 Haz 2024 |
35İzleyin | CVE-2023-6009İstismar yok | UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalationuserproplugin · userpro · CWE-266 | Yüksek8,8 | — | %0,9 | 22 Kas 2023 |
35İzleyin | CVE-2023-2440İstismar yok | UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalationuserproplugin · userpro · CWE-352 | Yüksek8,8 | — | %0,3 | 22 Kas 2023 |
35İzleyin | CVE-2023-2497İstismar yok | UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injectionuserproplugin · userpro · CWE-352 | Yüksek8,8 | — | %0,3 | 22 Kas 2023 |
34İzleyin | CVE-2023-2437Kavram kanıtı | UserPro <= 5.1.1 - Authentication Bypass to Administratoruserproplugin · userpro · CWE-288 | Yüksek8,1 | — | %6,7 | 22 Kas 2023 |
26İzleyin | CVE-2023-2446İstismar yok | UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcodeuserproplugin · userpro · CWE-200 | Orta6,5 | — | %0,8 | 22 Kas 2023 |
26İzleyin | CVE-2024-12821İstismar yok | Media Manager for UserPro <= 3.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Updateuserproplugin · media manager · CWE-862 | Orta6,5 | — | %0,4 | 30 Oca 2025 |
26İzleyin | CVE-2023-6007İstismar yok | UserPro <= 5.1.1 - Missing Authorization via multiple functionsuserproplugin · userpro · CWE-862 | Orta6,5 | — | %0,3 | 22 Kas 2023 |
24İzleyin | CVE-2018-16285İstismar yok | The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/aduserproplugin · userpro · CWE-79 | Orta6,1 | — | %1,3 | 6 Eyl 2018 |
24İzleyin | CVE-2023-2447İstismar yok | UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposureuserproplugin · userpro · CWE-352 | Orta6,1 | — | %0,2 | 22 Kas 2023 |
24İzleyin | CVE-2023-2438İstismar yok | UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdatauserproplugin · userpro · CWE-352 | Orta6,1 | — | %0,2 | 22 Kas 2023 |
21İzleyin | CVE-2023-2448İstismar yok | UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_templateuserproplugin · userpro · CWE-862 | Orta5,3 | — | %1,0 | 22 Kas 2023 |
21İzleyin | CVE-2024-0701İstismar yok | UserPro <= 5.1.6 - Disabled Membership Registration Bypassuserproplugin · userpro · CWE-602 | Orta5,3 | — | %0,6 | 5 Şub 2024 |
21İzleyin | CVE-2023-2439İstismar yok | The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, userproplugin · userpro · CWE-79 | Orta5,4 | — | %0,3 | 30 Oca 2024 |
17İzleyin | CVE-2023-6008İstismar yok | UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functionsuserproplugin · userpro · CWE-352 | Orta4,3 | — | %0,2 | 22 Kas 2023 |
- CVE-2019-1447049Planlayın
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/s
OrtaCVSS 6,1Kavram kanıtıEPSS %83instagram-php-api project · instagram-php-api4 Eyl 2019
- CVE-2017-1656247Planlayın
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentic
KritikCVSS 9,8Kavram kanıtıEPSS %27userproplugin · userpro9 Kas 2017
- CVE-2023-244939İzleyin
UserPro <= 5.1.1 - Insecure Password Reset Mechanism
KritikCVSS 9,8İstismar yokEPSS %1userproplugin · userpro22 Kas 2023
- CVE-2024-1282239İzleyin
Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Update
KritikCVSS 9,8İstismar yokEPSS %1userproplugin · media manager30 Oca 2025
- CVE-2024-3570039İzleyin
WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerability
KritikCVSS 9,8İstismar yokEPSS %0userproplugin · userpro4 Haz 2024
- CVE-2023-600935İzleyin
UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %1userproplugin · userpro22 Kas 2023
- CVE-2023-244035İzleyin
UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %0userproplugin · userpro22 Kas 2023
- CVE-2023-249735İzleyin
UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection
YüksekCVSS 8,8İstismar yokEPSS %0userproplugin · userpro22 Kas 2023
- CVE-2023-243734İzleyin
UserPro <= 5.1.1 - Authentication Bypass to Administrator
YüksekCVSS 8,1Kavram kanıtıEPSS %7userproplugin · userpro22 Kas 2023
- CVE-2023-244626İzleyin
UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode
OrtaCVSS 6,5İstismar yokEPSS %1userproplugin · userpro22 Kas 2023
- CVE-2024-1282126İzleyin
Media Manager for UserPro <= 3.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
OrtaCVSS 6,5İstismar yokEPSS %0userproplugin · media manager30 Oca 2025
- CVE-2023-600726İzleyin
UserPro <= 5.1.1 - Missing Authorization via multiple functions
OrtaCVSS 6,5İstismar yokEPSS %0userproplugin · userpro22 Kas 2023
- CVE-2018-1628524İzleyin
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/ad
OrtaCVSS 6,1İstismar yokEPSS %1userproplugin · userpro6 Eyl 2018
- CVE-2023-244724İzleyin
UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposure
OrtaCVSS 6,1İstismar yokEPSS %0userproplugin · userpro22 Kas 2023
- CVE-2023-243824İzleyin
UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata
OrtaCVSS 6,1İstismar yokEPSS %0userproplugin · userpro22 Kas 2023
- CVE-2023-244821İzleyin
UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template
OrtaCVSS 5,3İstismar yokEPSS %1userproplugin · userpro22 Kas 2023
- CVE-2024-070121İzleyin
UserPro <= 5.1.6 - Disabled Membership Registration Bypass
OrtaCVSS 5,3İstismar yokEPSS %1userproplugin · userpro5 Şub 2024
- CVE-2023-243921İzleyin
The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including,
OrtaCVSS 5,4İstismar yokEPSS %0userproplugin · userpro30 Oca 2024
- CVE-2023-600817İzleyin
UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions
OrtaCVSS 4,3İstismar yokEPSS %0userproplugin · userpro22 Kas 2023