CVE-2021-25076
WP User Frontend < 3.5.26 - SQL Injection to Reflected Cross-Site Scripting
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting
Productos afectados
Unknown · WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPressPoCs públicas encontradas — 3
githubgithub.com/abbarhissarh/CVE-2021-25076★ 3cve_referencepacketstormsecurity.com/files/166071/WordPress-WP-User-Frontend-3.5.25-SQL-Injection.htmlno verificadoexploitdbwww.exploit-db.com/exploits/50772no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →