WordPress security by component
UserPro - Community and User Profile
Plugin description
UserPro - Community and User Profile is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 14, 2025; the highest CVE/CNA score is 5.9.
Plugin slug:
userpro-community-and-user-profile-wordpress-pluginLatest vulnerability
CVE-2025-4187: UserPro - Community and User Profile: Filesystem traversal
UserPro - Community and User Profile is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
| Safe version |
|
||
|---|---|---|---|
| Jun 14, 2025 |
CVE-2025-4187
UserPro - Community and User Profile: Filesystem traversal
UserPro - Community and User Profile is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE5.9
NVDPending
|