What the vulnerability does
01Description
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.
Explanation of Vulnerability in Simple Terms
02Summary
WP User Frontend versions up to 4.2.8 lack proper authorization checks, allowing unauthenticated attackers to modify site data. The vulnerability requires no user interaction and can be exploited over the network. Site administrators should update immediately to prevent unauthorized changes to user-submitted content and site configuration.
What an attacker can do
03Attacker Capabilities
Modify or alter site data without logging in or having permission to do so.
Potential impact on your site
04Site Impact
Attackers can change user submissions, forms, or plugin settings without your knowledge or consent.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 29, 2026
Record updated