CVE-2025-3054
- EPSS 0.24%
- Veröffentlicht 05.06.2025 05:23:00
- Zuletzt bearbeitet 05.06.2025 20:12:23
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, ...
CVE-2023-45002
- EPSS 0.14%
- Veröffentlicht 02.01.2025 12:15:08
- Zuletzt bearbeitet 02.01.2025 12:15:08
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.
CVE-2024-38693
- EPSS 0.56%
- Veröffentlicht 29.08.2024 14:15:08
- Zuletzt bearbeitet 13.09.2024 20:35:41
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.
CVE-2023-47682
- EPSS 0.22%
- Veröffentlicht 17.05.2024 09:15:11
- Zuletzt bearbeitet 21.11.2024 08:30:40
Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.
CVE-2021-24649
- EPSS 0.41%
- Veröffentlicht 21.11.2022 11:15:12
- Zuletzt bearbeitet 30.04.2025 14:15:23
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker havi...
CVE-2021-25076
- EPSS 49.76%
- Veröffentlicht 24.01.2022 08:15:09
- Zuletzt bearbeitet 21.11.2024 05:54:18
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this cou...