WordPress Plugin Vulnerabilities
UserPro < 5.1.7 - Disabled Membership Registration Bypass
Description
The plugin is vulnerable to Security Feature Bypass, due to the use of client-side restrictions to enforce the 'Disabled registration' Membership feature within the plugin's General settings, allowing unauthenticated attackers to register an account even when account registration has been disabled by an administrator.
Affects Plugins
References
Miscellaneous
Original Researcher
Rob Stevens
Verified
No
WPVDB ID
Timeline
Publicly Published
2024-02-01 (about 2 years ago)
Added
2024-02-02 (about 2 years ago)
Last Updated
2024-02-02 (about 2 years ago)