Extension WordPress
Vulnérabilités UserPro – Community and User Profile WordPress Plugin
Cette page rassemble les failles publiées pour UserPro – Community and User Profile WordPress Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de UserPro – Community and User Profile WordPress Plugin
26 fiches
UserPro – Community and User Profile WordPress Plugin < 5.1.11 – Cross-Site Request Forgery
The UserPro – Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 5.1.11. This is due to missing or incorrect nonce validation on a function. This makes it…
[*, 5.1.11)
5.1.11
15/04/2026
Userpro <= 5.1.9 – Missing Authorization
The Userpro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.1.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-5.1.9
Non indiqué
25/12/2025
UserPro – Community and User Profile WordPress Plugin <= 5.1.10 – Unauthenticated Arbitrary File Read
The UserPro – Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 via the userpro_fbconnect() function. This makes it possible for unauthenticated attackers to read…
*-5.1.10
Non indiqué
13/06/2025
Userpro <= 5.1.9 – Missing Authorization
The Userpro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in versions up to, and including, 5.1.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
*-5.1.9
Non indiqué
19/12/2024
Userpro <= 5.1.9 – Reflected Cross-Site Scripting
The Userpro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-5.1.9
Non indiqué
19/12/2024
Userpro <= 5.1.9 – Authenticated (Contributor+) SQL Injection
The Userpro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.1.9
Non indiqué
19/12/2024
Userpro <= 5.1.9 – Unauthenticated Local File Inclusion
The Userpro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.1.9. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of…
*-5.1.9
Non indiqué
19/12/2024
UserPro <= 5.1.8 – Unauthenticated Account Takeover to Privilege Escalation
The UserPro – Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthenticated account takeover in all versions up to, and including 5.1.8. This makes it possible for unauthenticated attackers to take over user accounts…
5.1.8
5.1.9
21/05/2024
UserPro <= 5.1.6 – Disabled Membership Registration Bypass
The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use of client-side restrictions to enforce the 'Disabled registration' Membership feature within the plugin's…
*-5.1.6
5.1.7
01/02/2024
UserPro <= 5.1.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
5.1.5
5.1.6
30/11/2023
UserPro <= 5.1.0 – Cross-Site Request Forgery to PHP Object Injection
The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'import_settings' function. This makes it possible for unauthenticated attackers…
*-5.1.0
5.1.1
21/11/2023
UserPro <= 5.1.1 – Cross-Site Request Forgery via multiple functions
The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to…
*-5.1.1
5.1.2
21/11/2023
UserPro <= 5.1.4 – Authenticated (Subscriber+) Privilege Escalation
The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a…
*-5.1.4
5.1.5
21/11/2023
UserPro <= 5.1.1 – Insecure Password Reset Mechanism
The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (userpro_process_form).…
*-5.1.1
5.1.2
21/11/2023
UserPro <= 5.1.1 – Authentication Bypass to Administrator
The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it…
*-5.1.1
5.1.2
21/11/2023
UserPro <= 5.1.0 – Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata
The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'userpro_save_userdata' function. This makes it possible for unauthenticated attackers…
*-5.1.0
5.1.1
21/11/2023
UserPro <= 5.1.4 – Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template
The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' function in versions up to, and including, 5.1.4. This makes it possible for unauthenticated attackers to arbitrary…
*-5.1.4
5.1.5
21/11/2023
UserPro <= 5.1.1 – Cross-Site Request Forgery to Privilege Escalation
The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing nonce validation in the 'admin_page', 'userpro_verify_user' and 'verifyUnverifyAllUsers' functions. This makes it possible for unauthenticated…
*-5.1.1
5.1.2
21/11/2023
UserPro <= 5.1.1 – Missing Authorization via multiple functions
The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.1.1. This makes it…
*-5.1.1
5.1.2
21/11/2023
UserPro <= 5.1.1 – Sensitive Information Disclosure via Shortcode
The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1. This is due to insufficient restriction on sensitive user meta values that can be called via…
*-5.1.1
5.1.2
21/11/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.