Description
WordPress Plugin UserPro-Community and User Profile is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin UserPro-Community and User Profile version 4.9.20 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9.21 or latest
References
https://www.exploit-db.com/exploits/46083
https://packetstormsecurity.com/files/151022/WordPress-UserPro-Privilege-Escalation.html
https://www.wordfence.com/blog/2019/01/using-commercial-plugins-responsibly/
https://demo.userproplugin.com/wp-content/plugins/userpro/changelog.txt
Related Vulnerabilities
WordPress Plugin Gallery-Flagallery Photo Portfolio Multiple Vulnerabilities (2.00)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9414)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2004-0079)
WordPress Plugin BSK PDF Manager Multiple SQL Injection Vulnerabilities (1.3.2)