CVE-2025-58673: WordPress WP User Frontend Plugin <= 4.1.12 - Content Injection Vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in Tareq Hasan WP User Frontend allows Code Injection. This issue affects WP User Frontend: from n/a through 4.1.11.
Other sources
Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58673?
CVE-2025-58673 is classified as a high severity content injection vulnerability.
How do I fix CVE-2025-58673?
To mitigate CVE-2025-58673, update the WP User Frontend plugin to version 4.1.13 or later.
Which versions are affected by CVE-2025-58673?
CVE-2025-58673 affects WP User Frontend versions up to and including 4.1.12.
What kind of vulnerability is CVE-2025-58673?
CVE-2025-58673 is a content injection vulnerability that allows attackers to inject arbitrary code.
Who is the vendor for CVE-2025-58673?
The vendor for CVE-2025-58673 is weDevs, responsible for the WP User Frontend plugin.