Wp User Frontend
Vendor:
First CVE: Jan 24, 2022 · Active for 4 years
10
Total CVEs
More Total CVEs than 89% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wp User Frontend over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2022
4 years ago
Most Recent CVE
Jun 29, 2026
29 days ago
CVE Severity & Scoring
Wp User Frontend10 CVEs
60%
30%
10%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (50.0%)
High2 (20.0%)
None3 (30.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25076HIGH The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an | Jan 24, 2022 | 8.8 | 48 | NO | YES |
CVE-2026-57334MEDIUM Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | Jun 29, 2026 | 6.5 | 31 | NO | NO |
CVE-2021-24649CRITICAL The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created wi | Nov 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-42412MEDIUM Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WP User Frontend: from n | Apr 29, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-24364MEDIUM Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User F | Mar 25, 2026 | 6.5 | 22 | NO | NO |
CVE-2023-47682HIGH Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5. | May 17, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-38693HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Fronte | Aug 29, 2024 | 7.2 | 20 | NO | NO |
CVE-2025-58673MEDIUM Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from | Sep 22, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-58672MEDIUM Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User F | Sep 22, 2025 | 5.4 | 19 | NO | NO |
CVE-2023-45002MEDIUM Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a | Jan 2, 2025 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Wp User Frontend
Top CWEs
Versions
No cataloged versions.