userproplugin records
19 published records for vendor userproplugin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 5.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-862 Missing Authorization4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-266 Incorrect Privilege Assignment2
- CWE-287 Improper Authentication1
- CWE-620 Unverified Password Change1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2019-14470Proof of concept | cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/sinstagram-php-api project · instagram-php-api · CWE-79 | Medium6.1 | — | 83.0% | Sep 4, 2019 |
47Plan | CVE-2017-16562Proof of concept | The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authenticuserproplugin · userpro · CWE-287 | Critical9.8 | — | 27.4% | Nov 9, 2017 |
39Monitor | CVE-2023-2449No exploit | UserPro <= 5.1.1 - Insecure Password Reset Mechanismuserproplugin · userpro · CWE-620 | Critical9.8 | — | 0.9% | Nov 22, 2023 |
39Monitor | CVE-2024-12822No exploit | Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Updateuserproplugin · media manager · CWE-862 | Critical9.8 | — | 0.6% | Jan 30, 2025 |
39Monitor | CVE-2024-35700No exploit | WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerabilityuserproplugin · userpro · CWE-266 | Critical9.8 | — | 0.5% | Jun 4, 2024 |
35Monitor | CVE-2023-6009No exploit | UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalationuserproplugin · userpro · CWE-266 | High8.8 | — | 0.9% | Nov 22, 2023 |
35Monitor | CVE-2023-2440No exploit | UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalationuserproplugin · userpro · CWE-352 | High8.8 | — | 0.3% | Nov 22, 2023 |
35Monitor | CVE-2023-2497No exploit | UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injectionuserproplugin · userpro · CWE-352 | High8.8 | — | 0.3% | Nov 22, 2023 |
34Monitor | CVE-2023-2437Proof of concept | UserPro <= 5.1.1 - Authentication Bypass to Administratoruserproplugin · userpro · CWE-288 | High8.1 | — | 6.7% | Nov 22, 2023 |
26Monitor | CVE-2023-2446No exploit | UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcodeuserproplugin · userpro · CWE-200 | Medium6.5 | — | 0.8% | Nov 22, 2023 |
26Monitor | CVE-2024-12821No exploit | Media Manager for UserPro <= 3.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Updateuserproplugin · media manager · CWE-862 | Medium6.5 | — | 0.4% | Jan 30, 2025 |
26Monitor | CVE-2023-6007No exploit | UserPro <= 5.1.1 - Missing Authorization via multiple functionsuserproplugin · userpro · CWE-862 | Medium6.5 | — | 0.3% | Nov 22, 2023 |
24Monitor | CVE-2018-16285No exploit | The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/aduserproplugin · userpro · CWE-79 | Medium6.1 | — | 1.3% | Sep 6, 2018 |
24Monitor | CVE-2023-2447No exploit | UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposureuserproplugin · userpro · CWE-352 | Medium6.1 | — | 0.2% | Nov 22, 2023 |
24Monitor | CVE-2023-2438No exploit | UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdatauserproplugin · userpro · CWE-352 | Medium6.1 | — | 0.2% | Nov 22, 2023 |
21Monitor | CVE-2023-2448No exploit | UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_templateuserproplugin · userpro · CWE-862 | Medium5.3 | — | 1.0% | Nov 22, 2023 |
21Monitor | CVE-2024-0701No exploit | UserPro <= 5.1.6 - Disabled Membership Registration Bypassuserproplugin · userpro · CWE-602 | Medium5.3 | — | 0.6% | Feb 5, 2024 |
21Monitor | CVE-2023-2439No exploit | The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, userproplugin · userpro · CWE-79 | Medium5.4 | — | 0.3% | Jan 30, 2024 |
17Monitor | CVE-2023-6008No exploit | UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functionsuserproplugin · userpro · CWE-352 | Medium4.3 | — | 0.2% | Nov 22, 2023 |
- CVE-2019-1447049Plan
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/s
MediumCVSS 6.1Proof of conceptEPSS 83%instagram-php-api project · instagram-php-apiSep 4, 2019
- CVE-2017-1656247Plan
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentic
CriticalCVSS 9.8Proof of conceptEPSS 27%userproplugin · userproNov 9, 2017
- CVE-2023-244939Monitor
UserPro <= 5.1.1 - Insecure Password Reset Mechanism
CriticalCVSS 9.8No exploitEPSS 1%userproplugin · userproNov 22, 2023
- CVE-2024-1282239Monitor
Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Update
CriticalCVSS 9.8No exploitEPSS 1%userproplugin · media managerJan 30, 2025
- CVE-2024-3570039Monitor
WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerability
CriticalCVSS 9.8No exploitEPSS 0%userproplugin · userproJun 4, 2024
- CVE-2023-600935Monitor
UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation
HighCVSS 8.8No exploitEPSS 1%userproplugin · userproNov 22, 2023
- CVE-2023-244035Monitor
UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation
HighCVSS 8.8No exploitEPSS 0%userproplugin · userproNov 22, 2023
- CVE-2023-249735Monitor
UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection
HighCVSS 8.8No exploitEPSS 0%userproplugin · userproNov 22, 2023
- CVE-2023-243734Monitor
UserPro <= 5.1.1 - Authentication Bypass to Administrator
HighCVSS 8.1Proof of conceptEPSS 7%userproplugin · userproNov 22, 2023
- CVE-2023-244626Monitor
UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode
MediumCVSS 6.5No exploitEPSS 1%userproplugin · userproNov 22, 2023
- CVE-2024-1282126Monitor
Media Manager for UserPro <= 3.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
MediumCVSS 6.5No exploitEPSS 0%userproplugin · media managerJan 30, 2025
- CVE-2023-600726Monitor
UserPro <= 5.1.1 - Missing Authorization via multiple functions
MediumCVSS 6.5No exploitEPSS 0%userproplugin · userproNov 22, 2023
- CVE-2018-1628524Monitor
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/ad
MediumCVSS 6.1No exploitEPSS 1%userproplugin · userproSep 6, 2018
- CVE-2023-244724Monitor
UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposure
MediumCVSS 6.1No exploitEPSS 0%userproplugin · userproNov 22, 2023
- CVE-2023-243824Monitor
UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata
MediumCVSS 6.1No exploitEPSS 0%userproplugin · userproNov 22, 2023
- CVE-2023-244821Monitor
UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template
MediumCVSS 5.3No exploitEPSS 1%userproplugin · userproNov 22, 2023
- CVE-2024-070121Monitor
UserPro <= 5.1.6 - Disabled Membership Registration Bypass
MediumCVSS 5.3No exploitEPSS 1%userproplugin · userproFeb 5, 2024
- CVE-2023-243921Monitor
The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including,
MediumCVSS 5.4No exploitEPSS 0%userproplugin · userproJan 30, 2024
- CVE-2023-600817Monitor
UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions
MediumCVSS 4.3No exploitEPSS 0%userproplugin · userproNov 22, 2023