Code Injection Vulnerability in WP User Frontend by Tareq Hasan
CVE-2025-58673
5.4MEDIUM
What is CVE-2025-58673?
A code injection vulnerability has been discovered in the WP User Frontend plugin by Tareq Hasan, allowing attackers to inject arbitrary code. This security flaw affects versions from n/a up to 4.1.11, potentially enabling unauthorized access or actions on the WordPress sites using the plugin. Website administrators are urged to apply updates and implement security measures to mitigate this risk.
Affected Version(s)
WP User Frontend <= 4.1.11