Description
WordPress Plugin WP User Frontend-Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin WP User Frontend-Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission version 4.0.7 is affected; prior versions may also be affected.
Remediation
Update to plugin version 4.0.8 or latest
References
https://sansec.io/research/polyfill-supply-chain-attack
https://plugins.svn.wordpress.org/wp-user-frontend/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin BibleGet I/O Unspecified Vulnerability (3.4)
IBM WebSEAL Improper Input Validation Vulnerability (CVE-2019-4036)
Cherokee Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-2191)
OpenSSL Improper Input Validation Vulnerability (CVE-2016-6302)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0046)