S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 31, 2025

CVE-2023-2437 Scanner

CVE-2023-2437 Scanner - Authentication Bypass vulnerability in UserPro

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-2437
8.1
CVSScritical
Exploitable remotely over the internet · no authentication required.

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email. An attacker can leverage CVE-2023-2448 and CVE-2023-2446 to get the user's email address to successfully exploit this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
UserPro - Community and User Profile WordPress Pluginby n/a
0
Updated Aug 22, 2026View on NVD →
Detail

UserPro is a popular WordPress plugin used to enhance user profiles with social login capabilities. It's widely adopted by developers and website owners looking to implement advanced profile features on their WordPress sites. The plugin allows users to register and log in through various social media platforms, simplifying user management for administrators. It's especially beneficial for community sites and membership-based platforms due to its versatile integration and user-friendly interface. However, being widely used also makes it a notable target for attackers seeking vulnerabilities within well-distributed plugins. Regular updates and security assessments are crucial to maintaining its secure environment.

The vulnerability detected in UserPro allows attackers to bypass authentication via the userpro_fbconnect AJAX action. This critical flaw can be exploited to gain unauthorized access to accounts by manipulating certain parameters. Such breaches can lead to privilege escalation and the potential control of administrator-level accounts if left unchecked. The vulnerabilities are often tagged as severe due to their potential to compromise entire user bases. Vigilance in vulnerability detection and patching is indispensable to mitigate such threats. Regular plugin updates are essential to protect against evolving methods of exploitation.

The technical details of the authentication bypass in UserPro revolve around the manipulation of particular AJAX actions. The vulnerable endpoint is associated with the 'userpro_fbconnect' action, whereby inappropriate requests can allow unauthorized login attempts. Attackers can craft requests to simulate authenticated sessions by exploiting the parameters passed within the AJAX call. Successful exploitation could trigger unauthorized account access, allowing attackers to assume identities of legitimate users. This flaw highlights the importance of strict authentication measures and randomized token usage to prevent such bypass attacks.

Exploitation of this vulnerability could result in severe consequences, such as unauthorized data access and potential data manipulation. By bypassing authentication, malicious individuals can assume control over user accounts, leading to data breaches and unapproved content changes. This could compromise user trust and website integrity, especially if attackers gain access to sensitive information or administrative privileges. Website reputation might suffer extensively, necessitating costly remediation efforts. UserPro users are urged to implement security patches promptly and configure additional authentication layers if available.

REFERENCES

Solution Advice
  • Upgrade to the latest version of UserPro as soon as possible.
  • Implement additional authentication measures, such as two-factor authentication, where available.
  • Regularly review and audit user accounts for suspicious activity to detect unauthorized access early.
  • Consult security advisories and news from trusted sources to remain informed about updates or patches.
  • Consider deploying a Web Application Firewall (WAF) to block potential exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-2437 Scanner - Authentication Bypass vulnerability in UserPro | S4E