Description
WordPress Plugin UserPro-Community and User Profile is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass authentication mechanism and log in with full administrator access. WordPress Plugin UserPro-Community and User Profile version 4.9.17 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9.17.1 or latest
References
https://www.exploit-db.com/exploits/43117/
https://packetstormsecurity.com/files/144905/WordPress-UserPro-4.6.17-Authentication-Bypass.html
https://codecanyon.net/item/userpro-user-profiles-with-social-login/5958681
Related Vulnerabilities
WordPress Plugin Simple File List Multiple Vulnerabilities (3.2.4)
WordPress Plugin YITH PayPal Express Checkout for WooCommerce Security Bypass (1.2.5)
Moodle Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-9186)
WordPress Plugin Remove Schema Cross-Site Request Forgery (1.4)