Sensitive Information Disclosure in UserPro WordPress Plugin
CVE-2023-2446
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 22 November 2023
What is CVE-2023-2446?
The UserPro plugin for WordPress has a vulnerability that permits authenticated attackers with subscriber-level access to exploit the 'userpro' shortcode, leading to the unintended disclosure of sensitive user meta values. This exposure arises from inadequate restrictions imposed on these values, potentially enabling adversaries to obtain critical user information that could facilitate unauthorized access to higher-privileged accounts. Users should update to the latest version to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
UserPro - Community and User Profile WordPress Plugin * <= 5.1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved