Description
WordPress Plugin UserPro-Community and User Profile is prone to multiple vulnerabilities, including security bypass and privilege escalation vulnerabilities. An attacker may leverage these issues to perform otherwise restricted actions and subsequently perform arbitrary shortcode execution, or to bypass the expected capabilities check and perform otherwise restricted actions. WordPress Plugin UserPro-Community and User Profile version 5.1.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.5 or latest
References
Related Vulnerabilities
WordPress Plugin Login as User or Customer Security Bypass (1.7)
Restlet Framework Deserialization of Untrusted Data Vulnerability (CVE-2013-4271)
WordPress Plugin Advanced File Manager Directory Traversal (5.1)
WordPress Plugin WordPress Email Marketing-WP Email Capture Multiple Vulnerabilities (3.9.3)
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Request Forgery (1.5.2)