Description
WordPress Plugin UserPro-Community and User Profile is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin UserPro-Community and User Profile version 4.9.27 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9.28 or latest
References
Related Vulnerabilities
Oracle JRE CVE-2013-2466 Vulnerability (CVE-2013-2466)
PrestaShop Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-25170)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0704)
WordPress Plugin Search Types Custom Fields Widget Unspecified Vulnerability (1.3)
WordPress Plugin WP Helper Premium Cross-Site Scripting (4.2)