plugin

Userpro Mediamanager Vulnerabilities

2 known security issues reported for the Userpro Mediamanager WordPress plugin. Most recent disclosed Jan 30, 2025.

1 critical 1 high

Running Userpro Mediamanager on your site? Check whether your installed version is affected.

Scan your site free

Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Update

critical

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the add_capto_img() function in all versions up to, and including, 3.11.0. This makes it possible for unauthenticated attackers to update arbit...

CVSS:
9.8
Affected:
up to 3.11.0
Fix:
No patched version reported
Disclosed:
Jan 30, 2025

CVE-2024-12822 on NVD →

Media Manager for UserPro <= 3.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

high

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the upm_upload_media() function in all versions up to, and including, 3.12.0. This makes it possible for authenticated attackers, with Subscrib...

CVSS:
8.8
Affected:
up to 3.12.0
Fix:
No patched version reported
Disclosed:
Jan 30, 2025

CVE-2024-12821 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database