PeproDev Ultimate Profile Solutions Missing Authorization Vulnerability in WordPress

Vulnerability

A vulnerability exists in the PeproDev Ultimate Profile Solutions plugin for WordPress, specifically in versions 1.9.1 to 7.5.2. The issue arises from a lack of proper capability checks in the handel_ajax_req() function, allowing unauthorized users to modify arbitrary user metadata. This vulnerability could be exploited to prevent an administrator from accessing their site by setting the wp_capabilities metadata to 0.

Impact

Exploitation of this vulnerability allows for unauthorized users to change user metadata, potentially locking administrators out of their accounts.

Remediation

No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.