cleantalk
Vulnerabilities and Security Researches

WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss, 7431ce6590261438ff8d83691d0148a5de295091

Published on
Jun 25, 2024
Research Description
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 4.0.8 Various Plugins <= Various Version - Use of Polyfill.io Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Polyfill.io. Polyfill.io is a JavaScript library used to streamline delivery of content across older browsers and was taken over by malicious threat actors that used the service to redirect victims to malicious websites. While many WordPress plugins utilize Polyfill.io, not all of them may have been delivering malicious content. Regardless, it is recommended to update to a version of the plugin where Polyfill is no longer used or manually remove the use of Polyfill.io from the plugin.
Affected versions
max 4.0.8.
Status
vulnerable