Vulnerabilities and security researches forwp-user-frontend wp-user-frontend
Direction: ascendingJun 07, 2024
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2021-24649
- CVE, Research URL
- Date
- Nov 21, 2022
- Research Description
- The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary file access issue for example, or if the blog is using the default keys) to create an account with any role they want, such as admin
- Affected versions
-
max 3.5.29.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2021-25076
- CVE, Research URL
- Date
- Jan 24, 2022
- Research Description
- The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting
- Affected versions
-
max 3.5.26.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2023-47682
- CVE, Research URL
- Date
- May 17, 2024
- Research Description
- Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.
- Affected versions
-
max 3.6.6.
- Status
-
vulnerable
Jun 10, 2024
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2023-45002
- CVE, Research URL
- Date
- Jan 02, 2025
- Research Description
- Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.
- Affected versions
-
max 3.6.9.
- Status
-
vulnerable
Aug 04, 2024
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2024-38693
- CVE, Research URL
- Date
- Aug 29, 2024
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.
- Affected versions
-
max 4.0.8.
- Status
-
vulnerable
Oct 12, 2025
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2025-58672
- CVE, Research URL
- Date
- Sep 23, 2025
- Research Description
- Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12.
- Affected versions
-
max 4.1.13.
- Status
-
vulnerable
Jan 11, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2025-14047
- CVE, Research URL
- Date
- Jan 02, 2026
- Research Description
- The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including, 4.2.4. This makes it possible for unauthenticated attackers to delete attachment.
- Affected versions
-
max 4.2.5.
- Status
-
vulnerable
Mar 30, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-32485
- CVE, Research URL
- Date
- Mar 25, 2026
- Research Description
- Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.
- Affected versions
-
max 4.2.9.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-24364
- CVE, Research URL
- Date
- Mar 25, 2026
- Research Description
- Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5.
- Affected versions
-
max 4.2.6.
- Status
-
vulnerable
Apr 13, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-2233
- CVE, Research URL
- Date
- Mar 16, 2026
- Research Description
- The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to modify arbitrary posts (e.g. unpublish published posts and overwrite the contents) via the 'post_id' parameter.
- Affected versions
-
max 4.2.9.
- Status
-
vulnerable
Apr 15, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-1565
- CVE, Research URL
- Date
- Feb 27, 2026
- Research Description
- The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4.2.8. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Affected versions
-
max 4.2.9.
- Status
-
vulnerable
Apr 24, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2025-58673
- CVE, Research URL
- Date
- Sep 23, 2025
- Research Description
- Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12.
- Affected versions
-
max 4.1.13.
- Status
-
vulnerable
May 01, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-42412
- CVE, Research URL
- Date
- Apr 29, 2026
- Research Description
- Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.
- Affected versions
-
max 4.3.2.
- Status
-
vulnerable
May 09, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-5127
- CVE, Research URL
- Date
- May 08, 2026
- Research Description
- The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form submission, combined with unconditional deserialization via maybe_unserialize() when displaying post content. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP objects, which can be leveraged to execute arbitrary code, delete arbitrary files, or perform other malicious actions if a POP chain is present on the target system.
- Affected versions
-
max 4.3.2.
- Status
-
vulnerable
Jun 10, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-4058
- CVE, Research URL
- Date
- Jun 09, 2026
- Research Description
- The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel any user's subscription pack, including administrators.
- Affected versions
-
max 4.3.3.
- Status
-
vulnerable
Jun 16, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # 5dcd1f3f46eb9431cd0bc27046c14c9f7451b893
- CVE, Research URL
- Date
- Feb 08, 2016
- Research Description
- User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration [wp-user-frontend] < 2.3.11 WordPress WP User Frontend Plugin 2.3.10 - Unrestricted File Upload Because of this vulnerability, anyone can upload files to the web server by performing certain "wpuf_file_upload" or "wpuf_insert_image" actions. Upgrade the plugin.
- Affected versions
-
max 2.3.11.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # 41970c6f91db77a4fa1e39a0aa38651415b94c47
- CVE, Research URL
- Date
- Nov 18, 2021
- Research Description
- User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration [wp-user-frontend] < 3.5.25 WordPress WP User Frontend plugin <= 3.5.23 - SQL Injection (SQLi) vulnerability SQL Injection (SQLi) vulnerability discovered in WordPress WP User Frontend plugin (versions <= 3.5.23).
- Affected versions
-
max 3.5.25.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # ccd9b56c6ffe2d1ea77cee81dcd3d453c7ce6839
- CVE, Research URL
- Date
- Feb 08, 2016
- Research Description
- User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration [wp-user-frontend] < 2.3.11 WP User Frontend < 2.3.11 - Arbitrary File Upload The WP User Frontend plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpuf_file_upload' and 'wpuf_insert_image' AJAX actions in versions before 2.3.11. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- Affected versions
-
max 2.3.11.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # 80cdcbf03ddc1e138b20daf9bebce7cb12df1769
- CVE, Research URL
- Date
- Jul 03, 2024
- Research Description
- User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration [wp-user-frontend] < 4.0.8 WordPress WP User Frontend Plugin <= 4.0.7 is vulnerable to Backdoor <p>WordPress WP User Frontend Plugin <= 4.0.7 is vulnerable to Backdoor</p><p>Software: WP User Frontend</p><p>Link: https://wordpress.org/plugins/wp-user-frontend/#developers</p><p>Affected Version <= 4.0.7</p>
- Affected versions
-
max 4.0.8.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # bf156174-367c-4779-99c6-185129ee85e0
- CVE, Research URL
- Date
- -
- Research Description
- User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission [wp-user-frontend] < 2.3.11 WP User Frontend <= 2.3.10 - Unrestricted File Upload The WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress WordPress plugin was affected by an Unrestricted File Upload security vulnerability.
- Affected versions
-
max 2.3.11.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # 7431ce6590261438ff8d83691d0148a5de295091
- CVE, Research URL
- Date
- Jun 25, 2024
- Research Description
- User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration [wp-user-frontend] < 4.0.8 Various Plugins <= Various Version - Use of Polyfill.io Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Polyfill.io. Polyfill.io is a JavaScript library used to streamline delivery of content across older browsers and was taken over by malicious threat actors that used the service to redirect victims to malicious websites. While many WordPress plugins utilize Polyfill.io, not all of them may have been delivering malicious content. Regardless, it is recommended to update to a version of the plugin where Polyfill is no longer used or manually remove the use of Polyfill.io from the plugin.
- Affected versions
-
max 4.0.8.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # f6747162e6324b3d04a2631c53a4a6b20e051c1f
- CVE, Research URL
- Date
- Nov 18, 2021
- Research Description
- User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration [wp-user-frontend] < 3.5.25 WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress < 3.5.25 - Authenticated (Admin+) SQL Injection The WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions before 3.5.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with admin-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 3.5.25.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # 7458ac0a-7737-42a6-a430-7b3aa7564841
- CVE, Research URL
- Date
- -
- Research Description
- User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission [wp-user-frontend] < 3.5.25 WP User Frontend < 3.5.25 - Admin+ SQL Injection The plugin does not validate and escape the post_id parameter from the Subscribers list before using in a SQL statement, leading to an SQL injection
- Affected versions
-
max 3.5.25.
- Status
-
vulnerable
Jul 01, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-57334
- CVE, Research URL
- Date
- Jun 29, 2026
- Research Description
- Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
- Affected versions
-
max 4.3.8.
- Status
-
vulnerable
Jul 09, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-5459
- CVE, Research URL
- Date
- Jul 08, 2026
- Research Description
- The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to activate a free subscription pack for any user on the site, overwriting their existing paid subscription and causing loss of paid features.
- Affected versions
-
max 4.3.2.
- Status
-
vulnerable
Aug 09, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-14568
- CVE, Research URL
- Date
- Jul 27, 2026
- Research Description
- The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media.
- Affected versions
-
max 4.3.8.
- Status
-
vulnerable
Aug 30, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-14558
- CVE, Research URL
- Date
- Aug 28, 2026
- Research Description
- The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
- Affected versions
-
max 4.3.10.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-14567
- CVE, Research URL
- Date
- Aug 28, 2026
- Research Description
- The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.
- Affected versions
-
max 4.3.10.
- Status
-
vulnerable
Sep 25, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-95525
- CVE, Research URL
- Date
- Sep 23, 2026
- Research Description
- User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission [wp-user-frontend] < 4.3.12 CVE-2026-95525 [en] Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
- Affected versions
-
max 4.3.12.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-95524
- CVE, Research URL
- Date
- Sep 23, 2026
- Research Description
- User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission [wp-user-frontend] < 4.3.12 CVE-2026-95524 [en] Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
- Affected versions
-
max 4.3.12.
- Status
-
vulnerable
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-95523
- CVE, Research URL
- Date
- Sep 23, 2026
- Research Description
- User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission [wp-user-frontend] < 4.3.12 CVE-2026-95523 [en] Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
- Affected versions
-
max 4.3.12.
- Status
-
vulnerable
Oct 04, 2026
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submiss # CVE-2026-79618
- CVE, Research URL
- Date
- Oct 02, 2026
- Research Description
- The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
- Affected versions
-
max 4.3.12.
- Status
-
vulnerable