WordPress · Wp User Frontend · CVE-2026-14568
**Name of the Vulnerable Software and Affected Versions**
User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin versions prior to 4.3.8
**Description**
An issue exists where the software fails to correctly verify ownership before deleting an attachment. This allows unauthenticated attackers to permanently delete author-less attachments, including guest uploads and installed placeholder media.
**Recommendations**
Update User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin to version 4.3.8 or later.