References https://nvd.nist.gov/vuln/detail/CVE-2023-2437 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/userpro/userpro-511-authentication-bypass-to-administrator https://github.com/advisories/GHSA-w6q9-w8cf-jw9p https://access.redhat.com/security/cve/cve-2023-2437 https://hackhalt.com/threat/cve-2023-2437/ https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2437.yaml https://github.com/RxRCoder/CVE-2023-2437 https://www.incibe.es/index.php/en/incibe-cert/early-warning/vulnerabilities/cve-2023-2437 https://dbugs.ptsecurity.com/vulnerability/PT-2023-19534 https://cve.imfht.com/detail/CVE-2023-2437?lang=en
Related VulnerabilitiesPoCCVE-2019-14470: WordPress UserPro 4.9.32 - Cross-Site ScriptingPoCCVE-2023-2437: UserPro <= 5.1.1 - Authentication BypassrConfig userprocess.php 任意用户创建漏洞WordPress插件Userpro <4.9.17.1-身份验证绕过