VYPR
Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026

WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion

CVE-2026-14568

Description

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.