6.5
CVSSv3

CVE-2023-2446

Published: 22/11/2023 Updated: 30/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

userproplugin userpro

Exploits

WordPress UserPro plugin versions 511 and below suffer from an insecure password reset mechanism, information disclosure, and authentication bypass vulnerabilities Versions 514 and below suffer from privilege escalation and shortcode execution vulnerabilities ...