Skip to main content

Vendor/product archive

wedevs / wp_user_frontend CVEs

Beta · best-effort

3 CVEs tagged to wedevs / wp_user_frontend1 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2024-38693

Published Aug 29, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Front…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24649

Published Nov 21, 2022

The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created w…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-25076

Published Jan 24, 2022

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1