0xAbbarhSF / CVE-2021-25076

Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2021-25076-Exploit

Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)

CVE description:

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

ExploitDB:

Exploit Description:

About

Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)

License:GNU General Public License v3.0


Languages

Language:Python 100.0%