Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58276 | The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update. |
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | UserPro <= 5.1.4 - Authenticated (Subscriber+) Privilege Escalation | |
| Weaknesses | CWE-266 |
Tue, 10 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Userpro Community And User Profile Wordpress Plugin
Userpro Community And User Profile Wordpress Plugin userpro Community And User Profile Wordpress Plugin |
|
| CPEs | cpe:2.3:a:userpro_community_and_user_profile_wordpress_plugin:userpro_community_and_user_profile_wordpress_plugin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Userpro Community And User Profile Wordpress Plugin
Userpro Community And User Profile Wordpress Plugin userpro Community And User Profile Wordpress Plugin |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:30:39.714Z
Reserved: 2023-11-08T05:32:13.517Z
Link: CVE-2023-6009
Updated: 2024-08-02T08:21:17.115Z
Status : Modified
Published: 2023-11-22T16:15:15.643
Modified: 2026-04-08T19:18:54.117
Link: CVE-2023-6009
No data.
OpenCVE Enrichment
No data.
EUVD