Vulnerabilities > Wedevs > WP User Frontend > 3.1.7

DATE CVE VULNERABILITY TITLE RISK
2022-11-21 CVE-2021-24649 Unspecified vulnerability in Wedevs WP User Frontend
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption().
network
low complexity
wedevs
critical
9.8