Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend 4.0.7

    Fixed

    The WP User Frontend plugin for WordPress has a security issue that allows attackers to inject malicious code through the 'orderby' parameter. This can be done by users with administrator-level acces...

    Read More
  • Input validation vulnerability in OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) *

    Fixed

    Several add-ons for WordPress are at risk of being hacked and redirecting users to harmful websites. This is because they rely on a tool called Polyfill.io. Polyfill.io is a type of code that helps w...

    Read More
  • Access violation vulnerability in WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin 3.6.5

    Fixed

    The WP User Frontend plugin for WordPress is vulnerable to a security issue called 'Privilege Escalation'. This means that anyone with author-level access or higher, could use a registration form to ...

    Read More
  • Access violation vulnerability in WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin 3.6.8

    Fixed

    The WordPress User Frontend plugin, which is used with WordPress websites, has a security vulnerability that could allow people with subscriber-level access to do things they shouldn't be able to do....

    Read More
  • Input validation vulnerability in WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin 3.5.25

    Fixed

    (XSS) attacks.

    Read More
  • Input validation vulnerability in WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin 2.3.11

    Fixed

    The WP User Frontend plugin for WordPress is vulnerable to malicious file uploads in versions prior to 2.3.11. This means that unauthenticated attackers can upload any type of file to the website’s...

    Read More
  • Input validation vulnerability in WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin 3.5.25

    Fixed

    The WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress is vulnerable to a form of attack known as SQL Injection. This type of attack can allow someone w...

    Read More
  • Access violation vulnerability in WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin 3.5.28

    Fixed

    The WP User Frontend plugin for WordPress has a security issue that could allow someone to become an administrator without the correct credentials. This is because versions up to 3.5.28 of the plugin ...

    Read More
  • Input validation vulnerability in Appsero analytics tool 1.2.0 (41 plugins affected)

    Fixed

    The Appsero analytics tool

    Read More
  • Access violation vulnerability in Appsero analytics tool 1.2.1 (41 plugins affected)

    Fixed

    Several plugins are using the Appsero analytics tool, but it is vulnerable to authorization bypass due to a missing capability check on a function used for feedback submission in versions up to 1.2.1....

    Read More