8.8
CVSSv3

CVE-2023-6009

Published: 22/11/2023 Updated: 29/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

userproplugin userpro

Exploits

WordPress UserPro plugin versions 511 and below suffer from an insecure password reset mechanism, information disclosure, and authentication bypass vulnerabilities Versions 514 and below suffer from privilege escalation and shortcode execution vulnerabilities ...