UserPro - Community and User Profile WordPress Plugin

Explore UserPro - Community and User Profile WordPress Plugin vulnerabilities across all versions. Currently tracking 26 known vulnerabilities, including severity, impact, and patch status.

01234567891010.11.2017Today10.11.20179.8UserPro <= 4.9.17 - Authentication Bypass CVSS 9.8 · 10.11.201731.08.20186.1UserPro <= 4.9.23 - Unauthenticated Cross-Site Scripting CVSS 6.1 · 31.08.201810.09.20189.8UserPro <= 4.9.27 - Privilege Escalation CVSS 9.8 · 10.09.201803.01.201910.0UserPro <= 4.9.20 - Privilege Escalation CVSS 10.0 · 03.01.201925.08.20196.1UserPro <= 4.9.34 - Reflected Cross-Site Scripting CVSS 6.1 · 25.08.201921.11.20238.8UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation CVSS 8.8 · 21.11.20239.8UserPro <= 5.1.1 - Insecure Password Reset Mechanism CVSS 9.8 · 21.11.20239.8UserPro <= 5.1.1 - Authentication Bypass to Administrator CVSS 9.8 · 21.11.20236.1UserPro <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata CVSS 6.1 · 21.11.20236.5UserPro <= 5.1.4 - Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template CVSS 6.5 · 21.11.20236.1UserPro <= 5.1.1 - Cross-Site Request Forgery to Sensitive Information Exposure CVSS 6.1 · 21.11.20238.8UserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege Escalation CVSS 8.8 · 21.11.20236.3UserPro <= 5.1.1 - Cross-Site Request Forgery via multiple functions CVSS 6.3 · 21.11.20237.3UserPro <= 5.1.1 - Missing Authorization via multiple functions CVSS 7.3 · 21.11.20238.8UserPro <= 5.1.0 - Cross-Site Request Forgery to PHP Object Injection CVSS 8.8 · 21.11.20236.5UserPro <= 5.1.1 - Sensitive Information Disclosure via Shortcode CVSS 6.5 · 21.11.202330.11.20236.4UserPro <= 5.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 30.11.202301.02.20245.3UserPro <= 5.1.6 - Disabled Membership Registration Bypass CVSS 5.3 · 01.02.202421.05.20249.8UserPro <= 5.1.8 - Unauthenticated Account Takeover to Privilege Escalation CVSS 9.8 · 21.05.202419.12.20246.1Userpro <= 5.1.9 - Reflected Cross-Site Scripting CVSS 6.1 · 19.12.20249.8Userpro <= 5.1.9 - Unauthenticated Local File Inclusion CVSS 9.8 · 19.12.20244.3Userpro <= 5.1.9 - Missing Authorization CVSS 4.3 · 19.12.20246.5Userpro <= 5.1.9 - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 19.12.202413.06.20255.9UserPro - Community and User Profile WordPress Plugin <= 5.1.10 - Unauthenticated Arbitrary File Read CVSS 5.9 · 13.06.202525.12.20255.3Userpro <= 5.1.9 - Missing Authorization CVSS 5.3 · 25.12.202515.04.20264.3UserPro - Community and User Profile WordPress Plugin < 5.1.11 - Cross-Site Request Forgery CVSS 4.3 · 15.04.2026

Strategic Overview

Avg CVSSHigh
7.3/ 10
Patch Coverage77%
Open

6

Fixed

20

Get automatic notifications for all UserPro - Community and User Profile WordPress Plugin vulnerabilities before they are exploited.

Vulnerability Records

26 records
2026-04-15 00:00CVE-2025-53444
4.3
Medium
Ananda DhakalYes
2025-12-25 00:00CVE-2025-68608
5.3
Medium
Ananda DhakalNo
2025-06-13 19:48CVE-2025-4187
5.9
Medium
Trương Hữu Phúc (truonghuuphuc)No
2024-12-19 00:00CVE-2024-56210
6.1
Medium
Rafie MuhammadNo
2024-12-19 00:00CVE-2024-56214
9.8
Critical
Rafie MuhammadNo
2024-12-19 00:00CVE-2024-56211
4.3
Medium
Rafie MuhammadNo
2024-12-19 00:00CVE-2024-56212
6.5
Medium
Rafie MuhammadNo
2024-05-21 00:00CVE-2024-35700
9.8
Critical
Rafie MuhammadYes
2024-02-01 00:00CVE-2024-0701
5.3
Medium
Rob StevensYes
2023-11-30 00:00CVE-2023-2439
6.4
Medium
István MártonYes
Showing 1–10 of 26 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C