Medium severity5.3NVD Advisory· Published Sep 2, 2026
CVE-2026-17563
CVE-2026-17563
Description
The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.3.11
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.