Skip to content

Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)

License

Notifications You must be signed in to change notification settings

0xAbbarhSF/CVE-2021-25076

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 

Repository files navigation

CVE-2021-25076-Exploit

Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)

CVE description:

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

ExploitDB:

Exploit Description:

About

Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages