CVE-2026-32572
- EPSS 0.24%
- Veröffentlicht 06.10.2026 08:34:02
- Zuletzt bearbeitet 06.10.2026 15:04:25
Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions.
CVE-2026-95525
- EPSS 0.47%
- Veröffentlicht 23.09.2026 18:14:40
- Zuletzt bearbeitet 23.09.2026 19:39:08
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
CVE-2026-95523
- EPSS 0.34%
- Veröffentlicht 23.09.2026 18:14:39
- Zuletzt bearbeitet 23.09.2026 19:39:08
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95524
- EPSS 0.25%
- Veröffentlicht 23.09.2026 18:14:39
- Zuletzt bearbeitet 23.09.2026 20:17:24
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-81283
- EPSS 0.48%
- Veröffentlicht 02.09.2026 11:37:23
- Zuletzt bearbeitet 02.09.2026 13:54:48
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
CVE-2026-57334
- EPSS 0.19%
- Veröffentlicht 29.06.2026 13:36:37
- Zuletzt bearbeitet 29.06.2026 18:39:20
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
CVE-2026-42412
- EPSS 0.2%
- Veröffentlicht 29.04.2026 09:16:24
- Zuletzt bearbeitet 29.04.2026 21:15:41
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.
CVE-2026-32485
- EPSS 0.26%
- Veröffentlicht 25.03.2026 16:14:58
- Zuletzt bearbeitet 29.04.2026 10:17:13
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.
CVE-2026-24364
- EPSS 0.31%
- Veröffentlicht 25.03.2026 16:14:31
- Zuletzt bearbeitet 24.04.2026 16:32:53
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5.
CVE-2025-3054
- EPSS 0.8%
- Veröffentlicht 05.06.2025 05:23:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, ...