VYPR

Wp User Frontend

by WordPress

Source repositories

CVEs (26)

  • CVE-2025-14047MedJan 2, 2026
    risk 0.27cvss 5.3epss 0.01

    The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function…

  • CVE-2026-4058MedJun 9, 2026
    risk 0.21cvss 4.3epss 0.00

    The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and…

  • CVE-2026-12418MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.00

    The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing…

  • CVE-2026-12406MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.01

    The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.7. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-5459MedJul 8, 2026
    risk 0.00cvss 5.3epss 0.00

    The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on…

  • CVE-2026-57334MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

Page 2 of 2