Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Userpro
EPC
Developer
N/A
Latest version
N/A
Installations
N/A
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
5 present
17 fixed
9 Mitigation rules
Unauthenticated Arbitrary File Read vulnerability
<= 5.1.10
Jun 14, 2025
Local File Inclusion vulnerability
<= 5.1.9
Dec 19, 2024
SQL Injection vulnerability
<= 5.1.9
Dec 19, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 5.1.9
Dec 19, 2024
Authenticated Arbitrary User Meta Update vulnerability
<= 5.1.9
Dec 19, 2024
Unauthenticated Account Takeover vulnerability
<= 5.1.8
May 21, 2024
Disabled Membership Registration Bypass vulnerability
<= 5.1.6
Feb 2, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
5.1.5
Feb 1, 2024
Cross-Site Request Forgery via multiple functions vulnerability
<= 5.1.1
Nov 22, 2023
Cross-Site Request Forgery to PHP Object Injection vulnerability
<= 5.1.0
Nov 22, 2023
Missing Authorization via multiple functions vulnerability
<= 5.1.1
Nov 21, 2023
Cross-Site Request Forgery to Privilege Escalation vulnerability
<= 5.1.1
Nov 21, 2023
Cross-Site Request Forgery to Sensitive Information Exposure vulnerability
<= 5.1.1
Nov 21, 2023
Cross-Site Request Forgery to Stored Cross-Site Scripting via userpro_save_userdata vulnerability
<= 5.1.0
Nov 21, 2023
Authenticated (Subscriber+) Privilege Escalation vulnerability
<= 5.1.4
Nov 21, 2023
Authentication Bypass to Administrator vulnerability
<= 5.1.1
Nov 21, 2023
Missing Authorization to Arbitrary Shortcode Execution via userpro_shortcode_template vulnerability
<= 5.1.4
Nov 21, 2023
Sensitive Information Disclosure via Shortcode vulnerability
<= 5.1.1
Nov 21, 2023
Insecure Password Reset Mechanism vulnerability
<= 5.1.1
Nov 21, 2023
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
<= 4.9.33
Aug 27, 2019
Cross-Site Scripting (XSS) vulnerability
<= 4.9.23
Sep 9, 2018
Authentication Bypass Vulnerability
4.9.17
Nov 4, 2017