Description
WordPress Plugin UserPro-Community and User Profile is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass authentication mechanism and log in with full administrator access. WordPress Plugin UserPro-Community and User Profile version 4.9.17 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9.17.1 or latest
References
https://www.exploit-db.com/exploits/43117/
https://packetstormsecurity.com/files/144905/WordPress-UserPro-4.6.17-Authentication-Bypass.html
https://codecanyon.net/item/userpro-user-profiles-with-social-login/5958681
Related Vulnerabilities
Oracle JRE CVE-2012-0502 Vulnerability (CVE-2012-0502)
WordPress Plugin U Extended Comment 'fileurl' Parameter Arbitrary File Download (1.0.1)
SharePoint CVE-2020-0972 Vulnerability (CVE-2020-0972)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Cross-Site Scripting (3.4.2)
Owncloud Cross-site Scripting (XSS) Vulnerability (CVE-2020-16255)