WP User ProjectCVEs & Vulnerabilities
2 CVEs affecting WP User Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
wp user 2
CVE-2022-4049CRITICAL
The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
3 Jan 2023
9.8
CVSS
CVE-2021-25034MEDIUM
The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues
28 Feb 2022
6.1
CVSS
← PrevPage 1 / 1Next →