V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-0701
CVE
Medium

The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the u…

CVSS
5.3
Medium
EPSS
0.01
p43
Published
2024-01-01
Updated
2024-01-01
Description

The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use of client-side restrictions to enforce the 'Disabled registration' Membership feature within the plugin's General settings. This makes it possible for unauthenticated attackers to register an account even when account registration has been disabled by an administrator.

Tags · CWE
Pre-auth
CWE-602
CAPEC-21
CAPEC-31
CAPEC-162
CAPEC-202
CAPEC-207
CAPEC-208
CAPEC-383
CAPEC-384
CAPEC-385
CAPEC-386
CAPEC-387
CAPEC-388
Affected products
Userpro ≤ 5.1.6
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.006 · p43
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-383 · CWE-602
└ via CAPEC-21 · CWE-602
└ via CAPEC-21 · CWE-602
└ via CAPEC-21 · CWE-602
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
userpro*Tracked
Source databases
CVE