CVE-2017-16562: Userproplugin Userpro
Critical severity, CVSS 9.8. EPSS: 27.4% chance of exploitation in the next 30 days.
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.
Affected products
- Userproplugin Userpro: before 4.9.17.1 (fixed in 4.9.17.1)
Published 2017-11-10. Last modified 2026-06-17.