WP User Profiles
WP User Profiles has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Improper Privilege Management, behind 1 of the records (100%).
The one issue recorded for WP User Profiles has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by astra.r3verii. WP User Profiles is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2025-31524WP User Profiles <= 2.6.2 - Authenticated (Subscriber+) Privilege Escalation
Read the full analysisVulnerability Records

WP User Profiles
Author
John James Jacoby
WP User Profiles is a sophisticated way to edit users in WordPress. Includes all functionality from WordPress itself Includes 4 top-level “Sections” Includes an “Other” section to automatically work with third-party plugins Each section includes 1 or more meta-boxes Status meta-box allows easily changing user status Works great with multisite Network and User Dashboards Works great with WP User Groups and WP User Avatars plugins Recommended Plugins If you like this plugin, you’ll probably like these! WP User Profiles WP User Activity WP User Avatars WP User Groups WP User Signups WP Term Authors WP Term Colors WP Term Families WP Term Icons WP Term Images WP Term Locks WP Term Order WP Term Visibility WP Media Categories WP Pretty Filters WP Chosen
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C