Description
WordPress Plugin UserPro-Community and User Profile is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin UserPro-Community and User Profile version 4.9.20 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9.21 or latest
References
https://www.exploit-db.com/exploits/46083
https://packetstormsecurity.com/files/151022/WordPress-UserPro-Privilege-Escalation.html
https://www.wordfence.com/blog/2019/01/using-commercial-plugins-responsibly/
https://demo.userproplugin.com/wp-content/plugins/userpro/changelog.txt