CVE-2021-25076
HIGH EXPLOITEDWP User Frontend <3.5.26 - SQL Injection
Title source: llmDescription
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting
Exploits (5)
References (3)
Scores
CVSS v3
8.8
EPSS
0.5233
EPSS Percentile
97.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2021-12-21
CWE
CWE-89
Status
published
Products (1)
wedevs/wp_user_frontend
< 3.5.26
Published
Jan 24, 2022
Tracked Since
Feb 18, 2026