Description
WordPress Plugin UserPro-Community and User Profile is prone to multiple vulnerabilities, including security bypass and privilege escalation vulnerabilities. An attacker may leverage these issues to perform otherwise restricted actions and subsequently perform arbitrary shortcode execution, or to bypass the expected capabilities check and perform otherwise restricted actions. WordPress Plugin UserPro-Community and User Profile version 5.1.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.5 or latest
References
Related Vulnerabilities
WordPress Plugin Bookshelf Cross-Site Scripting (2.0.4)
WordPress Plugin Realteo Multiple Vulnerabilities (1.2.3)
PrestaShop Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2021-21302)
Nginx buffer underflow vulnerability
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2022-31779)