CVE-2026-2233
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to modify arbitrary posts (e.g. unpublish published posts and overwrite the contents) via the 'post_id' parameter.
| CWE | CWE-862 |
| Vendor | wedevs |
| Product | user frontend: ai powered frontend posting, user directory, profile, membership & user registration |
| Published | Mar 15, 2026 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for wedevs user frontend: ai powered frontend posting, user directory, profile, membership & user registration
Be the first to know when new medium vulnerabilities affecting wedevs user frontend: ai powered frontend posting, user directory, profile, membership & user registration are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
wedevs / User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration
0 โค 4.2.8
References
Credits
Supakiad S.