NA

CVE-2023-2448

Published: 22/11/2023 Updated: 04/12/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' function in versions up to, and including, 5.1.4. This makes it possible for unauthenticated malicious users to arbitrary shortcode execution. An attacker can leverage CVE-2023-2446 to get sensitive information via shortcode.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

userproplugin userpro

Exploits

WordPress UserPro plugin versions 511 and below suffer from an insecure password reset mechanism, information disclosure, and authentication bypass vulnerabilities Versions 514 and below suffer from privilege escalation and shortcode execution vulnerabilities ...