CVE-2023-45002
- EPSS 0.31%
- Veröffentlicht 02.01.2025 12:15:08
- Zuletzt bearbeitet 28.04.2026 19:21:27
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.
CVE-2024-38693
- EPSS 0.44%
- Veröffentlicht 29.08.2024 14:15:08
- Zuletzt bearbeitet 13.09.2024 20:35:41
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.
CVE-2023-47682
- EPSS 0.64%
- Veröffentlicht 17.05.2024 09:15:11
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.
CVE-2021-24649
- EPSS 0.65%
- Veröffentlicht 21.11.2022 11:15:12
- Zuletzt bearbeitet 30.04.2025 14:15:23
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker havi...
CVE-2021-25076
- EPSS 17.12%
- Veröffentlicht 24.01.2022 08:15:09
- Zuletzt bearbeitet 21.11.2024 05:54:18
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this cou...