Researchers have discovered a serious vulnerability in UserPro, a popular plugin for WordPress sites, developed by DeluxeThemes.

The UserPro plugin is used by more than 20,000 websites and allows users to create customizable front-end profiles and community websites.
Patchstack discovered the vulnerability in the password reset mechanism , specifically in the userpro_process_form function. Malicious unauthorized users can use the vulnerability to change the passwords of other users under certain conditions.
See also: LiteSpeed Cache plugin: Hackers gain control of WordPress sites via vulnerability
The vulnerability is tracked as CVE-2024-35700 and is due to improper handling of a "secret key" used during the password reset process .The key was not properly verified, and attackers could exploit it to gain unauthorized access to user accounts.
The vulnerability in the UserPro WordPress plugin is considered criticalbecause attackers could change users' passwords with a set of secret keys, which is typically used when users request a password reset .Attackers could initiate a reset and then tamper with the secret key before the legitimate user can complete the process.
See also: Wpeeper: Uses Compromised WordPress Sites to Hide C2 Servers
The vulnerability was present in all versions of the WordPress plugin UserPro up to version 5.1.8. The vendor released a new version, 5.1.9, to fix the vulnerability on April 29, 2024. It is recommended that you update your plugin to this version immediately.

Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.
Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
See also: WP Automatic WordPress plugin: Hackers exploit critical vulnerability
Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker compromises your WordPress site (e.g. through the vulnerability in the UserPro plugin) and corrupts the content, it can give the impression that you are not doing enough with your website.
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers ’ trust , preserving your company’s reputation, and staying on top of the competition.
Source: www.infosecurity-magazine.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
