Impact
An improper control of code generation vulnerability in the weDevs WP User Frontend plugin allows attackers to inject and execute arbitrary PHP code. Attackers can supply specially crafted input that is later rendered as code by the plugin, leading to Remote Code Execution with the privileges of the web server. This weakness is classified as CWE-94.
Affected Systems
Impact affects the weDevs WP User Frontend WordPress plugin, versions from the earliest releases through 4.1.12. Any WordPress website that installs or uses these plugin versions without patching is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver malicious input via the plugin’s content fields, so the likely attack vector is a web-based interaction with the WordPress site.
OpenCVE Enrichment
EUVD