Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Media Manager CRITICAL 9.8
CVE-2024-12822

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …

Fix: after 3.11.0
Fix from $2,300 2025-01-30
Media Manager MEDIUM 6.5
CVE-2024-12821

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …

Fix: after 3.12.0
Fix from $1,600 2025-01-30
Userpro CRITICAL 9.8
CVE-2024-35700

Incorrect Privilege Assignment vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.8.

Fix: 5.1.9+
Fix from $2,300 2024-06-04
Userpro MEDIUM 5.3
CVE-2024-0701

The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use of clie…

Fix: after 5.1.6
Fix from $1,600 2024-02-05
Userpro MEDIUM 5.4
CVE-2023-2439

The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due…

Fix: 5.1.6+
Fix from $1,600 2024-01-31
Userpro HIGH 8.8
CVE-2023-6009

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the…

Fix: after 5.1.4
Fix from $1,950 2023-11-22
Userpro MEDIUM 6.5
CVE-2023-6007

The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check o…

Fix: after 5.1.1
Fix from $1,600 2023-11-22
Userpro CRITICAL 9.8
CVE-2023-2449

The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin usin…

Fix: after 5.1.1
Fix from $2,300 2023-11-22
Userpro HIGH 8.8
CVE-2023-2440

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing nonce va…

Fix: after 5.1.1
Fix from $1,950 2023-11-22
Userpro HIGH 8.8
CVE-2023-2497

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incor…

Fix: after 5.1.0
Fix from $1,950 2023-11-22
Userpro HIGH 8.1
CVE-2023-2437EPSS 7%

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verifica…

Fix: after 5.1.1
Fix from $1,950 2023-11-22
Userpro MEDIUM 6.1
CVE-2023-2438

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incor…

Fix: after 5.1.0
Fix from $1,600 2023-11-22
Userpro MEDIUM 5.3
CVE-2023-2448

The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' f…

Fix: after 5.1.4
Fix from $1,600 2023-11-22
Userpro MEDIUM 6.5
CVE-2023-2446

The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1…

Fix: 5.1.2+
Fix from $1,600 2023-11-22
Userpro MEDIUM 6.1
CVE-2023-2447

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incor…

Fix: 5.1.2+
Fix from $1,600 2023-11-22
User Pro MEDIUM 6.1
CVE-2019-14470EPSS 83%

cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.ph…

Fix: after 4.9.32
Fix from $1,600 2019-09-04
Userpro MEDIUM 6.1
CVE-2018-16285

The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.…

Fix: after 4.9.23
Fix from $1,600 2018-09-06
Userpro CRITICAL 9.8
CVE-2017-16562EPSS 27%

The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and…

Fix: 4.9.17.1+
Fix from $2,300 2017-11-10