Input validation vulnerability in WP User Frontend Pro 4.1.3

The WP User Frontend Pro plugin for WordPress has a security issue that allows users to upload any type of file without proper validation. This means that people with certain levels of access can upload harmful files to the site’s server, potentially allowing them to execute remote code. The ‘Private Message’ module must be enabled and the Business version of the PRO software must be in use for this vulnerability to occur.

Detected in:

WP User Frontend Pro fixed vulnerable versions: >= * <= 4.1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.