Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WP User Frontend — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in WP User Frontend, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the WP User Frontend plugin, developed by frontenduser. It serves as a centralized repository for tracking security flaws within this specific WordPress extension, allowing researchers and administrators to monitor the historical security posture of the software. The vulnerabilities aggregated here span from the early release of the plugin through the present day, capturing a comprehensive timeline of security incidents. This collection includes a diverse range of weakness types, primarily focusing on injection flaws, cross-site scripting, and authorization bypasses that affect user input handling and front-end data submission processes. By consolidating these records, the page aims to provide a holistic view of how security risks have evolved within the WP User Frontend ecosystem over time, highlighting recurring patterns in development oversights and the subsequent remediation efforts. Visitors to this page can effectively track the vendor’s advisory history to understand the response time and transparency regarding critical patches. You can also use this resource to analyze the prevalence and impact of specific weakness classes within this plugin, aiding in risk assessment for sites relying on similar functionality. Furthermore, the archive allows users to look up the complete vulnerability history of WP User Frontend, facilitating informed decisions about plugin maintenance, updating schedules, and the potential need for alternative solutions to mitigate ongoing security exposure.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-79618 WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form 4.3 Medium 2026-10-02
CVE-2026-95525 WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability CWE-22 6.5 Medium 2026-09-23
CVE-2026-95524 WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability CWE-290 5.3 Medium 2026-09-23
CVE-2026-95523 WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability CWE-290 6.5 Medium 2026-09-23
CVE-2026-81283 WordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerability CWE-502 8.8 High 2026-09-02
CVE-2026-57334 WordPress WP User Frontend plugin <= 4.3.7 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-06-29
CVE-2026-42412 WordPress WP User Frontend plugin <= 4.3.1 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-04-29
CVE-2026-32485 WordPress WP User Frontend plugin <= 4.2.8 - Broken Access Control vulnerability CWE-862 7.5 High 2026-03-25
CVE-2026-24364 WordPress WP User Frontend plugin <= 4.2.5 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-03-25
CVE-2025-58673 WordPress WP User Frontend Plugin <= 4.1.12 - Content Injection Vulnerability CWE-94 5.4 Medium 2025-09-22
CVE-2025-58672 WordPress WP User Frontend Plugin <= 4.1.12 - Broken Access Control Vulnerability CWE-862 5.4 Medium 2025-09-22
CVE-2023-45002 WordPress WP User Frontend plugin <= 3.6.8 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-01-02
CVE-2024-38693 WordPress WP User Frontend plugin <= 4.0.7 - SQL Injection vulnerability CWE-89 7.6 High 2024-08-29
CVE-2023-47682 WordPress WP User Frontend plugin <= 3.6.5 - Authenticated Privilege Escalation vulnerability CWE-269 7.2 High 2024-05-17
CVE-2021-24649 WP User Frontend < 3.5.29 - Obscure Registration as Admin 8.8 - 2022-11-21

All 15 known CVE vulnerabilities affecting WP User Frontend with full Chinese analysis, references, and POCs where available.