CVE Vulnerabilities

CVE-2023-6009

Published: Nov 22, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the userpro_update_user_profile function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the wp_capabilities parameter during a profile update.

Affected Software

NameVendorStart VersionEnd Version
UserproUserproplugin*5.1.4 (including)

References