PT-2026-1040 · WordPress · Wp User Frontend

Angus Girvan

·

Published

2026-01-02

·

Updated

2026-01-02

·

CVE-2025-14047

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP User Frontend plugin for WordPress versions up to and including 4.2.4
Description The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress has an issue where a missing capability check on the Frontend Form Ajax::submit post() function allows unauthenticated attackers to delete attachments.
Recommendations Update to a version later than 4.2.4.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14047

Affected Products

Wp User Frontend