Userproplugin

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 19
    Known Exploited: 0
    5
    Critical Level Threats
    5
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-12822

    Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Update

    Last Modified: Apr 08, 2026
    Published: Jan 30, 2025

    CVE-2024-12821

    Media Manager for UserPro <= 3.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

    Last Modified: Apr 08, 2026
    Published: Jan 30, 2025

    CVE-2024-35700

    WordPress UserPro plugin <= 5.1.8 - Unauthenticated Account Takeover vulnerability

    Last Modified: Apr 23, 2026
    Published: Jun 04, 2024

    CVE-2024-0701

    UserPro <= 5.1.6 - Disabled Membership Registration Bypass

    Last Modified: Apr 08, 2026
    Published: Feb 05, 2024

    CVE-2023-2439

    The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Last Modified: Jun 17, 2025
    Published: Jan 31, 2024
    Items Per Page