Wedevs

Wp User Frontend

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 06.10.2026 08:34:02
  • Zuletzt bearbeitet 06.10.2026 15:04:25

Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions.

  • EPSS 0.47%
  • Veröffentlicht 23.09.2026 18:14:40
  • Zuletzt bearbeitet 23.09.2026 19:39:08

Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.

  • EPSS 0.34%
  • Veröffentlicht 23.09.2026 18:14:39
  • Zuletzt bearbeitet 23.09.2026 19:39:08

Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

  • EPSS 0.25%
  • Veröffentlicht 23.09.2026 18:14:39
  • Zuletzt bearbeitet 23.09.2026 20:17:24

Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

  • EPSS 0.48%
  • Veröffentlicht 02.09.2026 11:37:23
  • Zuletzt bearbeitet 02.09.2026 13:54:48

Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.

  • EPSS 0.19%
  • Veröffentlicht 29.06.2026 13:36:37
  • Zuletzt bearbeitet 29.06.2026 18:39:20

Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

  • EPSS 0.2%
  • Veröffentlicht 29.04.2026 09:16:24
  • Zuletzt bearbeitet 29.04.2026 21:15:41

Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.

  • EPSS 0.26%
  • Veröffentlicht 25.03.2026 16:14:58
  • Zuletzt bearbeitet 29.04.2026 10:17:13

Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.

  • EPSS 0.31%
  • Veröffentlicht 25.03.2026 16:14:31
  • Zuletzt bearbeitet 24.04.2026 16:32:53

Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5.

  • EPSS 0.8%
  • Veröffentlicht 05.06.2025 05:23:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, ...