plugin

Wp User Frontend Vulnerabilities

45 known security issues reported for the Wp User Frontend WordPress plugin. Most recent disclosed Jul 8, 2026.

2 critical 7 high 18 medium

Running Wp User Frontend on your site? Check whether your installed version is affected.

Scan your site free

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter

medium

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes it...

CVSS:
5.3
Affected:
up to 4.3.7
Fixed in:
4.3.8
Disclosed:
Jul 8, 2026

CVE-2026-12418 on NVD →

User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter

medium

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it p...

CVSS:
5.3
Affected:
up to 4.3.7
Fixed in:
4.3.8
Disclosed:
Jul 8, 2026

CVE-2026-12406 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite

medium

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This...

CVSS:
5.3
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Jul 7, 2026

CVE-2026-5459 on NVD →

User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration < 4.3.8 - Missing Authorization to Unauthenticated Media Attachment Deletion

medium

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 4.3.8 (exclusive). This makes it possible for unauthenticated attackers to...

CVSS:
5.3
Affected:
up to 4.3.8
Fixed in:
4.3.8
Disclosed:
Jul 6, 2026

CVE-2026-14568 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration <= 4.3.7 - Missing Authorization

medium

The User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.7. This makes it possible for unauthenticated attackers to perfo...

CVSS:
5.3
Affected:
up to 4.3.7
Fixed in:
4.3.8
Disclosed:
Jun 29, 2026

CVE-2026-57334 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation

medium

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it possible...

CVSS:
4.3
Affected:
up to 4.3.2
Fixed in:
4.3.3
Disclosed:
Jun 8, 2026

CVE-2026-4058 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection

high

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form s...

CVSS:
8.8
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
May 7, 2026

CVE-2026-5127 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Missing Authorization

medium

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to perform an un...

CVSS:
5.3
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Apr 27, 2026

CVE-2026-42412 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] <= 4.2.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5.

Affected:
up to 4.2.5
Fix:
No patched version reported
Disclosed:
Mar 25, 2026

CVE-2026-24364 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] <= 4.2.8 (unfixed)

unknown

[en] Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.

Affected:
up to 4.2.8
Fix:
No patched version reported
Disclosed:
Mar 25, 2026

CVE-2026-32485 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization

medium

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to perform a...

CVSS:
5.3
Affected:
up to 4.2.8
Fixed in:
4.2.9
Disclosed:
Mar 23, 2026

CVE-2026-32485 on NVD →

WP User Frontend - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter vulnerability

medium

Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter vulnerability

CVSS:
5.3
Affected:
up to 4.2.8
Fixed in:
4.2.9
Disclosed:
Mar 16, 2026

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter

medium

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for unauthent...

CVSS:
5.3
Affected:
up to 4.2.8
Fixed in:
4.2.9
Disclosed:
Mar 14, 2026

CVE-2026-2233 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.5 - Missing Authorization

medium

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.5. This makes it possible for authenticated attackers, with Subscrib...

CVSS:
4.3
Affected:
up to 4.2.5
Fixed in:
4.2.6
Disclosed:
Mar 10, 2026

CVE-2026-24364 on NVD →

WP User Frontend - Authenticated (Author+) Arbitrary File Upload vulnerability

high

Authenticated (Author+) Arbitrary File Upload vulnerability

CVSS:
8.8
Affected:
up to 4.2.8
Fixed in:
4.2.9
Disclosed:
Feb 27, 2026

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Authenticated (Author+) Arbitrary File Upload

high

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' functi...

CVSS:
8.8
Affected:
up to 4.2.8
Fixed in:
4.2.9
Disclosed:
Feb 26, 2026

CVE-2026-1565 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 4.2.5

unknown

[en] The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including,...

Affected:
up to 4.2.5
Fixed in:
4.2.5
Disclosed:
Jan 2, 2026

CVE-2025-14047 on NVD →

WP User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

medium

The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including, 4.2.4...

CVSS:
5.3
Affected:
up to 4.2.4
Fixed in:
4.2.5
Disclosed:
Jan 1, 2026

CVE-2025-14047 on NVD →

WP User Frontend <= 4.1.12 - Missing Authorization

medium

The WP User Frontend plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
5.4
Affected:
up to 4.1.12
Fixed in:
4.1.13
Disclosed:
Sep 22, 2025

CVE-2025-58672 on NVD →

WP User Frontend <= 4.1.12 - Authenticated (Subscriber+) Arbitrary Shortcode Execution

medium

The The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.1.12. This is due to the software allowing users to execute an action that does...

CVSS:
5.4
Affected:
up to 4.1.12
Fixed in:
4.1.13
Disclosed:
Sep 22, 2025

CVE-2025-58673 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 3.6.9

unknown

[en] Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.

Affected:
up to 3.6.9
Fixed in:
3.6.9
Disclosed:
Jan 2, 2025

CVE-2023-45002 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 4.0.8

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.

Affected:
up to 4.0.8
Fixed in:
4.0.8
Disclosed:
Aug 29, 2024

CVE-2024-38693 on NVD →

WP User Frontend <= 4.0.7 - Authenticated (Administrator+) SQL Injection

critical

The WP User Frontend plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 4.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...

CVSS:
9.1
Affected:
up to 4.0.7
Fixed in:
4.0.8
Disclosed:
Aug 1, 2024

CVE-2024-38693 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 4.0.8

unknown

<p>WordPress WP User Frontend Plugin <= 4.0.7 is vulnerable to Backdoor</p><p>Software: WP User Frontend</p><p>Link: https://wordpress.org/plugins/wp-user-frontend/#developers</p><p>Affected Version <= 4.0.7</p>

Affected:
up to 4.0.8
Fixed in:
4.0.8
Disclosed:
Jul 3, 2024

Various Plugins <= Various Version - Use of Polyfill.io

medium

Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Polyfill.io. Polyfill.io is a JavaScript library used to streamline delivery of content across older browsers and was taken over by malicious threat actors that used the service to redirect victims to m...

CVSS:
5.3
Affected:
up to 4.0.7
Fixed in:
4.0.8
Disclosed:
Jun 25, 2024

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 4.0.8

unknown

Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Polyfill.io. Polyfill.io is a JavaScript library used to streamline delivery of content across older browsers and was taken over by malicious threat actors that used the service to redirect victims to m...

Affected:
up to 4.0.8
Fixed in:
4.0.8
Disclosed:
Jun 25, 2024

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 3.6.6

unknown

[en] Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.

Affected:
up to 3.6.6
Fixed in:
3.6.6
Disclosed:
May 17, 2024

CVE-2023-47682 on NVD →

WP User Frontend <= 3.6.5 - Authenticated (Author+) Privilege Escalation

high

The WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.5. This is due to the plugin not providing sufficient controls on the ability to su...

CVSS:
8.8
Affected:
up to 3.6.5
Fixed in:
3.6.6
Disclosed:
Nov 9, 2023

CVE-2023-47682 on NVD →

WP User Frontend <= 3.6.8 - Missing Authorization via AJAX actions

medium

The WP User Frontend plugin for WordPress is vulnerable to unauthorized functionality use due to a missing capability check on several functions corresponding to AJAX actions in versions up to, and including, 3.6.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to install s...

CVSS:
4.3
Affected:
up to 3.6.8
Fixed in:
3.6.9
Disclosed:
Oct 3, 2023

CVE-2023-45002 on NVD →

Appsero <= 1.2.1 - Missing Authorization

medium

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...

CVSS:
4.3
Affected:
up to 3.6.0
Fixed in:
3.6.1
Disclosed:
Dec 16, 2022

Appsero <= 1.2.0 - Cross-Site Request Forgery

medium

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...

CVSS:
4.3
Affected:
up to 3.6.0
Fixed in:
3.6.1
Disclosed:
Dec 14, 2022

CVE-2022-47150 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 3.5.29

unknown

[en] The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrar...

Affected:
up to 3.5.29
Fixed in:
3.5.29
Disclosed:
Nov 21, 2022

CVE-2021-24649 on NVD →

WP User Frontend <= 3.5.28 - Privilege Escalation

high

The WP User Frontend plugin for WordPress is vulnerable to privilege escalation due to the default user role checking on the process_registration function in versions up to, and including, 3.5.28 which accepts user supplied input via the urhidden value. This makes it possible for attackers, under certain circumstances,...

CVSS:
8.1
Affected:
up to 3.5.28
Fixed in:
3.5.29
Disclosed:
Oct 31, 2022

CVE-2021-24649 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 3.5.26

unknown

[en] The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

Affected:
up to 3.5.26
Fixed in:
3.5.26
Disclosed:
Jan 24, 2022

CVE-2021-25076 on NVD →

WP User Frontend <= 3.5.25 - SQL Injection & Reflected Cross-Site Scripting

high

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

CVSS:
8.8
Affected:
up to 3.5.25
Fixed in:
3.5.26
Disclosed:
Dec 27, 2021

CVE-2021-25076 on NVD →

WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress < 3.5.25 - Authenticated (Admin+) SQL Injection

high

The WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions before 3.5.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...

CVSS:
7.2
Affected:
up to 3.5.25
Fixed in:
3.5.25
Disclosed:
Nov 18, 2021

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 3.5.25

unknown

SQL Injection (SQLi) vulnerability discovered in WordPress WP User Frontend plugin (versions <= 3.5.23).

Affected:
up to 3.5.25
Fixed in:
3.5.25
Disclosed:
Nov 18, 2021

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 3.5.25

unknown

The WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions before 3.5.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...

Affected:
up to 3.5.25
Fixed in:
3.5.25
Disclosed:
Nov 18, 2021

WP User Frontend < 2.3.11 - Arbitrary File Upload

critical

The WP User Frontend plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpuf_file_upload' and 'wpuf_insert_image' AJAX actions in versions before 2.3.11. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server whic...

CVSS:
9.8
Affected:
up to 2.3.11
Fixed in:
2.3.11
Disclosed:
Feb 8, 2016

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 2.3.11

unknown

Because of this vulnerability, anyone can upload files to the web server by performing certain "wpuf_file_upload" or "wpuf_insert_image" actions. Upgrade the plugin.

Affected:
up to 2.3.11
Fixed in:
2.3.11
Disclosed:
Feb 8, 2016

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 2.3.11

unknown

The WP User Frontend plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpuf_file_upload' and 'wpuf_insert_image' AJAX actions in versions before 2.3.11. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server whic...

Affected:
up to 2.3.11
Fixed in:
2.3.11
Disclosed:
Feb 8, 2016

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 2.3.11

unknown

The WP User Frontend &ndash; Membership, Profile, Registration &amp; Post Submission Plugin for WordPress WordPress plugin was affected by an Unrestricted File Upload security vulnerability.

Affected:
up to 2.3.11
Fixed in:
2.3.11

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 3.6.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.6.1
Fixed in:
3.6.1

CVE-2022-47150 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] <= 4.1.12 (unfixed)

unknown
Affected:
up to 4.1.12
Fix:
No patched version reported

CVE-2025-58672 on NVD →

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration [wp-user-frontend] < 3.5.25

unknown

The plugin does not validate and escape the post_id parameter from the Subscribers list before using in a SQL statement, leading to an SQL injection

Affected:
up to 3.5.25
Fixed in:
3.5.25

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database