Lucene search

K
wpvulndbWpvulndbWPVDB-ID:BF539A59-045A-437B-BB35-EC286AAB87E2
HistoryFeb 02, 2024 - 12:00 a.m.

UserPro < 5.1.7 - Disabled Membership Registration Bypass

2024-02-0200:00:00
wpscan.com
3
userpro
security feature bypass
client-side restrictions
disabled registration
general settings

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

20.5%

Description The plugin is vulnerable to Security Feature Bypass, due to the use of client-side restrictions to enforce the ‘Disabled registration’ Membership feature within the plugin’s General settings, allowing unauthenticated attackers to register an account even when account registration has been disabled by an administrator.

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

20.5%

Related for WPVDB-ID:BF539A59-045A-437B-BB35-EC286AAB87E2