Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-25076 — Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated) | Kitploit
Tools/GitHubGitHub/abbarhissarh/cve-2021-25076
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubabbarhissarh/cve-2021-25076

CVE-2021-25076

Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)

View Repository
3114 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-25076-Exploit

Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)

CVE description:

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

  • https://nvd.nist.gov/vuln/detail/CVE-2021-25076

ExploitDB:

  • https://www.exploit-db.com/exploits/50772

Exploit Description:

  • Vendor Homepage: https://wedevs.com/

  • Software Link: https://downloads.wordpress.org/plugin/wp-user-frontend.3.5.25.zip

  • Version: Up to 3.5.25

  • Tested on Ubuntu 20.04

  • 🕊️ Twitter:

@0xAbbarhSF
Tweet
Download Tool