๐Ÿ” CVE Alert

CVE-2026-79618

MEDIUM 4.3

WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.

Vendor unknown
Product wp user frontend
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp user frontend

Be the first to know when new medium vulnerabilities affecting unknown wp user frontend are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / WP User Frontend
0 < 4.3.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/a11bf097-3829-4baa-878c-80b113c5a744/

Credits

Erwan LR (WPScan) WPScan