VYPR

Wp User Frontend

by WordPress

Source repositories

CVEs (29)

  • CVE-2021-24649CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and…

  • CVE-2026-81283HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.01

    Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.

  • CVE-2026-19116HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object…

  • CVE-2025-3054HigJun 5, 2025
    risk 0.57cvss 8.8epss 0.01

    The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2021-25076HigJan 24, 2022
    risk 0.55cvss 8.8epss 0.17

    The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected…

  • CVE-2025-3055HigJun 5, 2025
    risk 0.53cvss 8.1epss 0.01

    The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with…

  • CVE-2026-5127HigMay 8, 2026
    risk 0.50cvss 8.8epss 0.01

    The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking…

  • CVE-2026-1565HigFeb 26, 2026
    risk 0.50cvss 8.8epss 0.01

    The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the…

  • CVE-2026-32485HigMar 25, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.

  • CVE-2024-38693HigAug 29, 2024
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.

  • CVE-2026-14558HigAug 28, 2026
    risk 0.47cvss 7.2epss 0.01

    The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to…

  • CVE-2023-47682HigMay 17, 2024
    risk 0.47cvss 7.2epss 0.01

    Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.

  • CVE-2026-95525MedSep 23, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.

  • CVE-2026-95523MedSep 23, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

  • CVE-2026-42412MedApr 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.

  • CVE-2026-24364MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5.

  • CVE-2025-58673MedSep 22, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12.

  • CVE-2025-58672MedSep 22, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12.

  • CVE-2026-95524MedSep 23, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

  • CVE-2026-17563MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately…

Page 1 of 2