CVE-2017-16562
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 27%
from disclosure to weapon0 days
Published on NVDNov 9
1st PoCNov 4
VulnCheck+1852d
exploitation probability
27%top 2% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/43117/unverifiedexploitdbwww.exploit-db.com/exploits/43117unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.