Vulnerabilities > Userproplugin > Userpro > 4.9.21

DATE CVE VULNERABILITY TITLE RISK
2023-11-22 CVE-2023-6009 Unspecified vulnerability in Userproplugin Userpro
The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function.
network
low complexity
userproplugin
8.8
2023-11-22 CVE-2023-2446 Unspecified vulnerability in Userproplugin Userpro
The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1.
network
low complexity
userproplugin
6.5
2023-11-22 CVE-2023-2447 Cross-Site Request Forgery (CSRF) vulnerability in Userproplugin Userpro
The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1.
network
low complexity
userproplugin CWE-352
6.1
2018-09-06 CVE-2018-16285 Cross-site Scripting vulnerability in Userproplugin Userpro
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
4.3