Wedevs

Wp User Frontend

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 05.06.2025 05:23:00
  • Zuletzt bearbeitet 05.06.2025 20:12:23

The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, ...

  • EPSS 0.14%
  • Veröffentlicht 02.01.2025 12:15:08
  • Zuletzt bearbeitet 02.01.2025 12:15:08

Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.

  • EPSS 0.56%
  • Veröffentlicht 29.08.2024 14:15:08
  • Zuletzt bearbeitet 13.09.2024 20:35:41

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.

  • EPSS 0.22%
  • Veröffentlicht 17.05.2024 09:15:11
  • Zuletzt bearbeitet 21.11.2024 08:30:40

Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 21.11.2022 11:15:12
  • Zuletzt bearbeitet 30.04.2025 14:15:23

The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker havi...

Exploit
  • EPSS 49.76%
  • Veröffentlicht 24.01.2022 08:15:09
  • Zuletzt bearbeitet 21.11.2024 05:54:18

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this cou...