« Volver al listado

Wedevs

Wedevs WP User Frontend: vulnerabilidades y CVE

Wedevs WP User Frontend tiene 18 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE18
Últimos 12 meses10
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-79618Media (4.3)0.18%—2 oct 2026
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to…
CVE-2026-95525Media (6.5)0.47%—23 sept 2026
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
CVE-2026-95524Media (5.3)0.25%—23 sept 2026
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95523Media (6.5)0.34%—23 sept 2026
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-81283Alta (8.8)0.52%—2 sept 2026
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
CVE-2026-57334Media (6.5)0.33%—29 jun 2026
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
CVE-2026-42412Media (6.5)0.33%—29 abr 2026
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.
CVE-2026-32485Alta (7.5)0.38%—25 mar 2026
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.
CVE-2026-24364Media (6.5)0.31%—25 mar 2026
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5.
CVE-2025-14047Media (5.3)0.90%—2 ene 2026
The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing…
CVE-2025-58673Media (5.4)0.23%—22 sept 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12.
CVE-2025-58672Media (5.4)0.27%—22 sept 2025
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12.
CVE-2025-3055Alta (8.1)0.81%—5 jun 2025
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() function in all versions up to, and including, 4.1.3. This…
CVE-2023-45002Media (4.3)0.31%—2 ene 2025
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.
CVE-2024-38693Alta (7.2)0.44%—29 ago 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.
CVE-2023-47682Alta (7.2)0.64%—17 may 2024
Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.
CVE-2021-24649Crítica (9.8)0.69%—21 nov 2022
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption().…
CVE-2021-25076Alta (8.8)17%—24 ene 2022
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1078.001 Default Accounts2
  3. T1190 Exploit Public-Facing Application2
  4. T1059 Command and Scripting Interpreter1
  5. T1078 Valid Accounts1
  6. T1485 Data Destruction1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Wedevs