Vulnerabilities > Userproplugin > Userpro > 4.9.23

DATE CVE VULNERABILITY TITLE RISK
2023-11-22 CVE-2023-2446 Unspecified vulnerability in Userproplugin Userpro
The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1.
network
low complexity
userproplugin
6.5
2023-11-22 CVE-2023-2447 Cross-Site Request Forgery (CSRF) vulnerability in Userproplugin Userpro
The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1.
network
low complexity
userproplugin CWE-352
6.1
2018-09-06 CVE-2018-16285 Cross-site Scripting vulnerability in Userproplugin Userpro
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
4.3