WP User Frontend < 3.5.26 - SQL Injection to Reflected Cross-Site Scripting
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 17%
from disclosure to weapon28 days
Published on NVDJan 24
1st PoC+28d
VulnCheckDec 21
exploitation probability
17%top 3% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting
Affected products
Unknown · WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPresspublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/50772unverifiedgithubgithub.com/abbarhissarh/CVE-2021-25076★ 3cve_referencepacketstormsecurity.com/files/166071/WordPress-WP-User-Frontend-3.5.25-SQL-Injection.htmlunverifiedvulncheckvulncheck.com/xdb/d3f1e43b652eunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.