What the vulnerability does
01Description
Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userpro: from n/a through <= 5.1.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
What the vulnerability does
Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userpro: from n/a through <= 5.1.9.
Explanation of Vulnerability in Simple Terms
Userpro versions up to 5.1.9 contain a vulnerability allowing attackers to execute arbitrary actions on the site. The attack requires user interaction—typically a victim clicking a malicious link—and can affect the confidentiality, integrity, and availability of the site. No authentication is required from the attacker's side.
What an attacker can do
Execute arbitrary actions on the site, potentially compromising user data and site functionality.
Potential impact on your site
Site data and functionality could be compromised if users are tricked into clicking malicious links.
Conditions required to exploit
Victim must click a malicious link or visit an attacker-controlled page; no attacker authentication needed.
Key dates
External resources
Related vulnerabilities