CVE-2017-16562: Userproplugin Userpro

Critical severity, CVSS 9.8. EPSS: 27.4% chance of exploitation in the next 30 days.

The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.

Affected products

Published 2017-11-10. Last modified 2026-06-17.