Unknown User Frontend
6 known vulnerabilities in Unknown User Frontend, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-75824 CVSS 5.3 medium The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account…
- CVE-2026-75823 CVSS 7.4 high The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing…
- CVE-2026-17563 CVSS 5.3 medium The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post…
- CVE-2026-19116 CVSS 8.8 high The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post…
- CVE-2026-14567 CVSS 5.3 medium The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated…
- CVE-2026-14558 CVSS 7.2 high The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post…