Extension WordPress
Vulnérabilités User registration & user profile – UserPlus
Cette page rassemble les failles publiées pour User registration & user profile – UserPlus, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de User registration & user profile – UserPlus
5 fiches
UserPlus <= 2.0 – Privilege Escalation
The User registration & user profile – UserPlus plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to gain administrator privileges.
*-2.0
Non indiqué
18/11/2024
UserPlus <= 2.0 – Missing Authorization via Multiple Functions
The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated…
*-2.0
Non indiqué
09/10/2024
UserPlus <= 2.0 – Unauthenticated Privilege Escalation
The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated attackers to specify their user…
*-2.0
Non indiqué
09/10/2024
UserPlus <= 2.0 – Authenticated (Editor+) Registration Form Update to Privilege Escalation
The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. This makes it possible for authenticated attackers, with editor-level…
*-2.0
Non indiqué
09/10/2024
UserPlus <= 2.0 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The UserPlus plugin for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to modify plugin options, including injecting malicious…
*-2.0
Non indiqué
12/04/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.