CVE-2026-17563: WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form

Published Sep 2, 2026
·
Updated

The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.

Affected Software

1 affected component
WP User Frontend<4.3.11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade wordpress/plugin/user-frontend to a version that resolves this vulnerability.

    Fixed in 4.3.11

Event History

Sep 2, 2026
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to unauthorized post creation?

Sites using WP User Frontend versions earlier than 4.3.11 are exposed if they have frontend post-submission forms restricted to paying subscribers. The subscription check is applied when the form is rendered but not when a submission is processed.

2

Does an attacker need an account or subscription to exploit this?

No. The vulnerability allows unauthenticated users to submit posts through forms intended for paying subscribers.

3

Can unauthorized submissions become publicly visible immediately?

Yes, if the affected form is configured to immediately publish submitted posts. Otherwise, the impact is limited by that form's post-status configuration.

4

What should be checked after updating?

Review posts created through affected frontend forms, particularly any that were configured for immediate publication, for unexpected unauthenticated submissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203