WordPress Plugin Vulnerabilities

UserPro < 5.1.7 - Disabled Membership Registration Bypass

Description

The plugin is vulnerable to Security Feature Bypass, due to the use of client-side restrictions to enforce the 'Disabled registration' Membership feature within the plugin's General settings, allowing unauthenticated attackers to register an account even when account registration has been disabled by an administrator.

Affects Plugins

Fixed in 5.1.7

References

Miscellaneous

Original Researcher
Rob Stevens
Verified
No

Timeline

Publicly Published
2024-02-01 (about 2 years ago)
Added
2024-02-02 (about 2 years ago)
Last Updated
2024-02-02 (about 2 years ago)

Other