CVE-2021-25076: WP User Frontend < 3.5.26 - SQL Injection to Reflected Cross-Site Scripting
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-25076?
CVE-2021-25076 is a vulnerability in the WP User Frontend WordPress plugin before version 3.5.26 that allows SQL injection and potential Reflected Cross-Site Scripting.
How does CVE-2021-25076 impact users?
CVE-2021-25076 allows an attacker to inject malicious SQL queries and potentially execute arbitrary code or access sensitive information.
What software versions are affected by CVE-2021-25076?
WP User Frontend WordPress plugin versions up to exclusive 3.5.26 are affected by CVE-2021-25076.
What is the severity of CVE-2021-25076?
CVE-2021-25076 has a severity rating of 8.8 (high).
How can I mitigate the risk of CVE-2021-25076?
To mitigate the risk of CVE-2021-25076, users should update to WP User Frontend WordPress plugin version 3.5.26 or later.