What the vulnerability does
01Description
The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use of client-side restrictions to enforce the 'Disabled registration' Membership feature within the plugin's General settings. This makes it possible for unauthenticated attackers to register an account even when account registration has been disabled by an administrator.
Explanation of Vulnerability in Simple Terms
02Summary
UserPro plugin versions up to 5.1.6 contain a flaw that allows attackers to modify data on the site without authentication. The vulnerability requires only network access and no user interaction. Site administrators should update to a version newer than 5.1.6 to prevent unauthorized changes to site content or settings.
What an attacker can do
03Attacker Capabilities
Modify site data or settings without logging in.
Potential impact on your site
04Site Impact
Attackers can alter site content, user data, or plugin settings without your knowledge or permission.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
February 5, 2024
CVE published
April 8, 2026
Record updated