CVE-2025-58672: WordPress WP User Frontend Plugin <= 4.1.12 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Tareq Hasan WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.1.11.
Other sources
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58672?
CVE-2025-58672 is classified as a medium severity vulnerability due to its broken access control issues.
How do I fix CVE-2025-58672?
To fix CVE-2025-58672, upgrade the WP User Frontend plugin to version 4.1.13 or later.
What are the risks associated with CVE-2025-58672?
The risks associated with CVE-2025-58672 include unauthorized access to user data and modification of content.
Which versions of WP User Frontend are affected by CVE-2025-58672?
CVE-2025-58672 affects WP User Frontend versions up to and including 4.1.12.
Who is the vendor for CVE-2025-58672?
The vendor for CVE-2025-58672 is weDevs, the developers of the WP User Frontend plugin.