What the vulnerability does
01Description
Missing Authorization vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.9.
Explanation of Vulnerability in Simple Terms
Userpro versions up to 5.1.9 lack proper authorization checks, allowing authenticated users with low privileges to read, modify, or delete sensitive data and functionality. An attacker with a basic user account can escalate their access to perform actions restricted to administrators. No user interaction is required once the attacker is logged in.
What an attacker can do
Read, modify, or delete sensitive data and site functionality with a low-privilege user account.
Potential impact on your site
Any registered user can access admin-level operations, compromising user data, site settings, and content integrity.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities