Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

UserPro - Community and User Profile WordPress Plugin — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in UserPro - Community and User Profile WordPress Plugin, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities affecting UserPro, a WordPress plugin developed by mndnetworks that manages community and user profiles. It aggregates data regarding common weakness types such as cross-site scripting, broken access control, and injection flaws that have been reported for this specific software component. The collection covers all identified vulnerabilities discovered from the plugin’s initial release through early 2024, providing a comprehensive historical view of its security posture. By reviewing this aggregated data, users can track vendor advisories to stay informed about patches and mitigation strategies released by the development team. Visitors can also use this resource to understand the prevalence and impact of specific weakness classes within the context of WordPress ecosystems. Furthermore, individuals can look up the product’s vulnerability history to assess long-term security trends and evaluate the reliability of the plugin for their websites. This information is essential for site administrators and security researchers seeking to make informed decisions about plugin usage and risk management. The data is organized to facilitate easy navigation through different vulnerability categories and release timelines, ensuring that users can quickly locate relevant details without sifting through unrelated noise. Maintaining an up-to-date awareness of these issues helps prevent potential exploitation by malicious actors targeting outdated or unpatched installations.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2025-4187 UserPro - Community and User Profile WordPress Plugin <= 5.1.10 - Unauthenticated Arbitrary File Read CWE-22 5.9 Medium 2025-06-14
CVE-2024-0701 UserPro <= 5.1.6 - Disabled Membership Registration Bypass CWE-602 5.3 Medium 2024-02-05
CVE-2023-2439 WordPress plugin UserPro 安全漏洞 6.4 Medium 2024-01-31
CVE-2023-2497 UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection CWE-352 8.8 High 2023-11-22
CVE-2023-6008 UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions CWE-352 6.3 Medium 2023-11-22
CVE-2023-6009 UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation CWE-266 8.8 High 2023-11-22
CVE-2023-2449 UserPro <= 5.1.1 - Insecure Password Reset Mechanism CWE-620 9.8 Critical 2023-11-22
CVE-2023-2437 UserPro <= 5.1.1 - Authentication Bypass to Administrator CWE-288 9.8 Critical 2023-11-22
CVE-2023-2438 UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata CWE-352 6.1 Medium 2023-11-22
CVE-2023-2448 UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template CWE-862 6.5 Medium 2023-11-22
CVE-2023-2440 UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation CWE-352 8.8 High 2023-11-22
CVE-2023-6007 UserPro <= 5.1.1 - Missing Authorization via multiple functions CWE-862 7.3 High 2023-11-22
CVE-2023-2446 UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode CWE-200 6.5 Medium 2023-11-22
CVE-2023-2447 UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposure CWE-352 6.1 Medium 2023-11-22

All 14 known CVE vulnerabilities affecting UserPro - Community and User Profile WordPress Plugin with full Chinese analysis, references, and POCs where available.