Description
WordPress Plugin UserPro-Community and User Profile is prone to multiple vulnerabilities, including security bypass and privilege escalation vulnerabilities. An attacker may leverage these issues to perform otherwise restricted actions and subsequently perform arbitrary shortcode execution, or to bypass the expected capabilities check and perform otherwise restricted actions. WordPress Plugin UserPro-Community and User Profile version 5.1.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.5 or latest
References
Related Vulnerabilities
Oracle JRE CVE-2011-3546 Vulnerability (CVE-2011-3546)
WordPress Plugin Admin Bar User Switching Cross-Site Scripting (1.0.4)
WordPress Plugin SEOPress, on-site SEO Cross-Site Scripting (5.0.3)
PostgreSQL Other Vulnerability (CVE-2004-0977)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-37914)