Input validation vulnerability in Front End Users 3.2.28

The Front End Users plugin for WordPress has a security vulnerability that allows attackers to use time-based SQL Injection. This happens when they manipulate the ‘order’ parameter in versions 3.2.28 and below. The problem is caused by the plugin not properly handling the user’s input and not preparing the SQL query well enough. This makes it possible for attackers with Contributor-level access or higher to add their own queries to the existing ones, which can lead to them getting confidential information from the database.

Detected in:

Front End Users open vulnerable versions: >= * <= 3.2.28

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.