CVE-2017-16562 | UserPro Plugin up to 4.9.17.0 on WordPress up_auto_log access control (EDB-43117 / Nessus ID 110482)
A vulnerability was found in UserPro Plugin up to 4.9.17.0 on WordPress and classified as critical. This affects an unknown function. The manipulation of the argument up_auto_log as part of Parameter results in improper access controls.
This vulnerability is known as CVE-2017-16562. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.