Unauthorized Access Vulnerability in UserPro Plugin for WordPress
CVE-2023-2448
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 22 November 2023
What is CVE-2023-2448?
The UserPro plugin for WordPress has a flaw due to a missing capability check on the 'userpro_shortcode_template' function. This vulnerability allows unauthorized users to execute arbitrary shortcodes, potentially leading to unauthorized access to sensitive data. Attackers can exploit this weakness without authentication, compromising user data security. It is crucial for site owners to update to the latest version and implement necessary security measures to defend against this type of attack.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
UserPro - Community and User Profile WordPress Plugin * <= 5.1.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved