« Back to list

User-meta

User-meta User Meta: vulnerabilities and CVEs

User-meta User Meta has 3 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-9693High (8)0.56%—Sep 11, 2025
The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the postInsertUserProcess function in all…
CVE-2024-9262Medium (6.5)0.41%—Nov 9, 2024
The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.1 via the getUser() due to missing…
CVE-2024-33575Medium (5.3)1.1%—Apr 29, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in User Meta user-meta.This issue affects User Meta: from n/a through 3.0.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1203 Exploitation for Client Execution1
  2. T1565.002 Transmitted Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by User-meta