Description
WordPress Plugin UserPro-Community and User Profile is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass authentication mechanism and log in with full administrator access. WordPress Plugin UserPro-Community and User Profile version 4.9.17 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9.17.1 or latest
References
https://www.exploit-db.com/exploits/43117/
https://packetstormsecurity.com/files/144905/WordPress-UserPro-4.6.17-Authentication-Bypass.html
https://codecanyon.net/item/userpro-user-profiles-with-social-login/5958681