CVE-2025-14047: WP User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'FrontendFormAjax::submitpost' function in all versions up to, and including, 4.2.4. This makes it possible for unauthenticated attackers to delete attachment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14047?
CVE-2025-14047 is classified as a high severity vulnerability due to the potential for unauthorized data loss.
How do I fix CVE-2025-14047?
To fix CVE-2025-14047, update the WP User Frontend plugin to version 4.2.5 or later.
What components are affected by CVE-2025-14047?
CVE-2025-14047 affects the Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission features of the WP User Frontend plugin.
What type of vulnerability is CVE-2025-14047?
CVE-2025-14047 is a data exposure vulnerability caused by a missing capability check during the post submission process.
Which versions of the WP User Frontend plugin are vulnerable to CVE-2025-14047?
Versions of the WP User Frontend plugin up to and including 4.2.4 are vulnerable to CVE-2025-14047.