İçeriğe atla
Noroxi

userproplugin kayıtları

userproplugin üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%5,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

19 kayıt
  • CVE-2019-14470
    49Planlayın

    cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/s

    OrtaCVSS 6,1Kavram kanıtıEPSS %83

    instagram-php-api project · instagram-php-api4 Eyl 2019

  • CVE-2017-16562
    47Planlayın

    The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentic

    KritikCVSS 9,8Kavram kanıtıEPSS %27

    userproplugin · userpro9 Kas 2017

  • CVE-2023-2449
    39İzleyin

    UserPro <= 5.1.1 - Insecure Password Reset Mechanism

    KritikCVSS 9,8İstismar yokEPSS %1

    userproplugin · userpro22 Kas 2023

  • CVE-2024-12822
    39İzleyin

    Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Update

    KritikCVSS 9,8İstismar yokEPSS %1

    userproplugin · media manager30 Oca 2025

  • CVE-2024-35700
    39İzleyin

    WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    userproplugin · userpro4 Haz 2024

  • CVE-2023-6009
    35İzleyin

    UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation

    YüksekCVSS 8,8İstismar yokEPSS %1

    userproplugin · userpro22 Kas 2023

  • CVE-2023-2440
    35İzleyin

    UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation

    YüksekCVSS 8,8İstismar yokEPSS %0

    userproplugin · userpro22 Kas 2023

  • CVE-2023-2497
    35İzleyin

    UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection

    YüksekCVSS 8,8İstismar yokEPSS %0

    userproplugin · userpro22 Kas 2023

  • CVE-2023-2437
    34İzleyin

    UserPro <= 5.1.1 - Authentication Bypass to Administrator

    YüksekCVSS 8,1Kavram kanıtıEPSS %7

    userproplugin · userpro22 Kas 2023

  • CVE-2023-2446
    26İzleyin

    UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode

    OrtaCVSS 6,5İstismar yokEPSS %1

    userproplugin · userpro22 Kas 2023

  • CVE-2024-12821
    26İzleyin

    Media Manager for UserPro <= 3.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

    OrtaCVSS 6,5İstismar yokEPSS %0

    userproplugin · media manager30 Oca 2025

  • CVE-2023-6007
    26İzleyin

    UserPro <= 5.1.1 - Missing Authorization via multiple functions

    OrtaCVSS 6,5İstismar yokEPSS %0

    userproplugin · userpro22 Kas 2023

  • CVE-2018-16285
    24İzleyin

    The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/ad

    OrtaCVSS 6,1İstismar yokEPSS %1

    userproplugin · userpro6 Eyl 2018

  • CVE-2023-2447
    24İzleyin

    UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposure

    OrtaCVSS 6,1İstismar yokEPSS %0

    userproplugin · userpro22 Kas 2023

  • CVE-2023-2438
    24İzleyin

    UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata

    OrtaCVSS 6,1İstismar yokEPSS %0

    userproplugin · userpro22 Kas 2023

  • CVE-2023-2448
    21İzleyin

    UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template

    OrtaCVSS 5,3İstismar yokEPSS %1

    userproplugin · userpro22 Kas 2023

  • CVE-2024-0701
    21İzleyin

    UserPro <= 5.1.6 - Disabled Membership Registration Bypass

    OrtaCVSS 5,3İstismar yokEPSS %1

    userproplugin · userpro5 Şub 2024

  • CVE-2023-2439
    21İzleyin

    The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including,

    OrtaCVSS 5,4İstismar yokEPSS %0

    userproplugin · userpro30 Oca 2024

  • CVE-2023-6008
    17İzleyin

    UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions

    OrtaCVSS 4,3İstismar yokEPSS %0

    userproplugin · userpro22 Kas 2023