Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Userproplugin Subscribe
Filtered by product Userpro
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16562 1 Userproplugin 1 Userpro 2019-10-02 7.5 HIGH 9.8 CRITICAL
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.
CVE-2018-16285 1 Userproplugin 1 Userpro 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.