Extension WordPress

Vulnérabilités UserPro – Community and User Profile WordPress Plugin

Cette page rassemble les failles publiées pour UserPro – Community and User Profile WordPress Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

26Vulnérabilités
7Critiques
20Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de UserPro – Community and User Profile WordPress Plugin

26 fiches

CVE-2025-53444 Moyenne · 4,3
UserPro – Community and User Profile WordPress Plugin

UserPro – Community and User Profile WordPress Plugin < 5.1.11 – Cross-Site Request Forgery

The UserPro – Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 5.1.11. This is due to missing or incorrect nonce validation on a function. This makes it…

Versions affectées

[*, 5.1.11)

Correctif

5.1.11

Publication

15/04/2026

CVE-2025-4187 Moyenne · 5,9
UserPro – Community and User Profile WordPress Plugin

UserPro – Community and User Profile WordPress Plugin <= 5.1.10 – Unauthenticated Arbitrary File Read

The UserPro – Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 via the userpro_fbconnect() function. This makes it possible for unauthenticated attackers to read…

Versions affectées

*-5.1.10

Correctif

Non indiqué

Publication

13/06/2025

CVE-2024-56210 Moyenne · 6,1
UserPro – Community and User Profile WordPress Plugin

Userpro <= 5.1.9 – Reflected Cross-Site Scripting

The Userpro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-5.1.9

Correctif

Non indiqué

Publication

19/12/2024

CVE-2024-35700 Critique · 9,8
UserPro – Community and User Profile WordPress Plugin

UserPro <= 5.1.8 – Unauthenticated Account Takeover to Privilege Escalation

The UserPro – Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthenticated account takeover in all versions up to, and including 5.1.8. This makes it possible for unauthenticated attackers to take over user accounts…

Versions affectées

5.1.8

Correctif

5.1.9

Publication

21/05/2024

CVE-2023-2439 Moyenne · 6,4
UserPro – Community and User Profile WordPress Plugin

UserPro <= 5.1.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

5.1.5

Correctif

5.1.6

Publication

30/11/2023

CVE-2023-2497 Élevée · 8,8
UserPro – Community and User Profile WordPress Plugin

UserPro <= 5.1.0 – Cross-Site Request Forgery to PHP Object Injection

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'import_settings' function. This makes it possible for unauthenticated attackers…

Versions affectées

*-5.1.0

Correctif

5.1.1

Publication

21/11/2023

CVE-2023-6008 Moyenne · 6,3
UserPro – Community and User Profile WordPress Plugin

UserPro <= 5.1.1 – Cross-Site Request Forgery via multiple functions

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to…

Versions affectées

*-5.1.1

Correctif

5.1.2

Publication

21/11/2023

CVE-2023-6009 Élevée · 8,8
UserPro – Community and User Profile WordPress Plugin

UserPro <= 5.1.4 – Authenticated (Subscriber+) Privilege Escalation

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a…

Versions affectées

*-5.1.4

Correctif

5.1.5

Publication

21/11/2023

CVE-2023-2449 Critique · 9,8
UserPro – Community and User Profile WordPress Plugin

UserPro <= 5.1.1 – Insecure Password Reset Mechanism

The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (userpro_process_form).…

Versions affectées

*-5.1.1

Correctif

5.1.2

Publication

21/11/2023

CVE-2023-2438 Moyenne · 6,1
UserPro – Community and User Profile WordPress Plugin

UserPro <= 5.1.0 – Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'userpro_save_userdata' function. This makes it possible for unauthenticated attackers…

Versions affectées

*-5.1.0

Correctif

5.1.1

Publication

21/11/2023

CVE-2023-2448 Moyenne · 6,5
UserPro – Community and User Profile WordPress Plugin

UserPro <= 5.1.4 – Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template

The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' function in versions up to, and including, 5.1.4. This makes it possible for unauthenticated attackers to arbitrary…

Versions affectées

*-5.1.4

Correctif

5.1.5

Publication

21/11/2023

CVE-2023-2440 Élevée · 8,8
UserPro – Community and User Profile WordPress Plugin

UserPro <= 5.1.1 – Cross-Site Request Forgery to Privilege Escalation

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing nonce validation in the 'admin_page', 'userpro_verify_user' and 'verifyUnverifyAllUsers' functions. This makes it possible for unauthenticated…

Versions affectées

*-5.1.1

Correctif

5.1.2

Publication

21/11/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités