CVE-2026-32485: WordPress WP User Frontend plugin <= 4.2.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32485?
CVE-2026-32485 is classified as a broken access control vulnerability that can lead to unauthorized actions being performed by users.
How do I fix CVE-2026-32485?
To mitigate CVE-2026-32485, update the WP User Frontend plugin to version 4.2.9 or later.
Which versions of WP User Frontend are affected by CVE-2026-32485?
CVE-2026-32485 affects all versions of the WP User Frontend plugin up to and including version 4.2.8.
What types of attacks can CVE-2026-32485 enable?
CVE-2026-32485 can allow attackers to exploit incorrectly configured access control security levels, potentially compromising user data.
Who is the vendor responsible for the WP User Frontend plugin affected by CVE-2026-32485?
The vendor responsible for the WP User Frontend plugin affected by CVE-2026-32485 is weDevs.