Wpuserplus develops the Userplus plugin, a narrowly scoped WordPress extension that exhibits vulnerability patterns centered on authorization and privilege-handling weaknesses, including CSRF, improper privilege management, and missing or incorrectly assigned access controls. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpuserplus over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9518CRITICAL The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_up | Oct 10, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-9519HIGH The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and | Oct 10, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-0824MEDIUM The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attack | Jan 16, 2024 | 6.5 | 17 | NO | NO |
CVE-2024-9520MEDIUM The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to | Oct 10, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpuserplus.
Media articles that mention a CVE ID that affects a product developed by Wpuserplus — matched by CVE ID, not by vendor name.