CVE-2026-79618
WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
| Vendor | unknown |
| Product | wp user frontend |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp user frontend
Be the first to know when new medium vulnerabilities affecting unknown wp user frontend are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / WP User Frontend
0 < 4.3.12
References
Credits
Erwan LR (WPScan) WPScan