cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foruserplus userplus

Direction: ascending
Jun 07, 2024

User registration & user profile – UserPlus # CVE-2023-0824

CVE, Research URL

CVE-2023-0824

Date
Jan 16, 2024
Research Description
The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.
Affected versions
Min -, max -.
Status
vulnerable
Oct 11, 2024

User registration & user profile – UserPlus # CVE-2024-9519

CVE, Research URL

CVE-2024-9519

Date
Oct 10, 2024
Research Description
The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. This makes it possible for authenticated attackers, with editor-level permissions or above, to update the registration form role to administrator, which leads to privilege escalation.
Affected versions
Min -, max -.
Status
vulnerable

User registration & user profile – UserPlus # CVE-2024-9518

CVE, Research URL

CVE-2024-9518

Date
Oct 10, 2024
Research Description
The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parameter during a registration.
Affected versions
Min -, max -.
Status
vulnerable

User registration & user profile – UserPlus # CVE-2024-9520

CVE, Research URL

CVE-2024-9520

Date
Oct 10, 2024
Research Description
The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers with subscriber-level permissions or above, to add, modify, or delete user meta and plugin options.
Affected versions
Min -, max -.
Status
vulnerable
Nov 22, 2024

User registration & user profile – UserPlus # CVE-2024-52442

CVE, Research URL

CVE-2024-52442

Date
Nov 20, 2024
Research Description
User registration &amp; user profile – UserPlus [userplus] <= 2.0 (unfixed) CVE-2024-52442 [en] Incorrect Privilege Assignment vulnerability in Userplus UserPlus allows Privilege Escalation.This issue affects UserPlus: from n/a through 2.0.
Affected versions
Min -, max -.
Status
vulnerable