Unauthorized Access to User Data in UserPlus Plugin for WordPress
CVE-2024-9520
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 10 October 2024
What is CVE-2024-9520?
The UserPlus plugin for WordPress is affected by a vulnerability that allows unauthorized access, alteration, and potential loss of data due to a missing capability check in several of its functions. This flaw impacts all versions up to and including 2.0, enabling authenticated attackers with subscriber-level permissions or higher to manipulate user meta data and plugin options. Such access may lead to serious implications for user security and data integrity within dependent WordPress sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
User registration & user profile – UserPlus * <= 2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved