Impact
The vulnerability in the UserPro – Community and User Profile WordPress Plugin allows unauthenticated attackers to perform directory traversal through the userpro_fbconnect() function, enabling them to read arbitrary files on the server. This weakness is a classic example of CWE‑22. Because the flaw does not require authentication or elevated privileges, content such as configuration files, database credentials, or private user data may be exposed, compromising the confidentiality of the affected infrastructure.
Affected Systems
The flaw affects all installations of the UserPro plugin for WordPress up to and including version 5.1.10. Site owners running any of these versions on WordPress should assess whether the plugin is in active use and whether the file permissions and server configuration could expose sensitive files. The plugin is distributed via the CodeCanyon marketplace and is commonly used to add social login and profile features to WordPress sites.
Risk and Exploitability
The CVSS score of 5.9 classifies this issue as medium severity, and the EPSS score of 1 % suggests that exploitation is possible but not widespread. The vulnerability is not part of the CISA KEV list, but because the bug permits unauthenticated file reads, attackers could quickly gain useful information. The attack vector is web‑based, requiring only a crafted request to the vulnerable function, and no additional authentication or privileged access is needed.
OpenCVE Enrichment
EUVD