CVE-2026-42412: WordPress WP User Frontend plugin <= 4.3.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WP User Frontend: from n/a through 4.3.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42412?
CVE-2026-42412 is classified as a Broken Access Control vulnerability impacting WP User Frontend plugin versions up to 4.3.1.
How do I fix CVE-2026-42412?
To fix CVE-2026-42412, update the WP User Frontend plugin to the latest version that addresses this vulnerability.
What versions are affected by CVE-2026-42412?
CVE-2026-42412 affects all versions of the WP User Frontend plugin up to and including version 4.3.1.
What are the risks of CVE-2026-42412?
The risks of CVE-2026-42412 include unauthorized access to user data and potential exploitation of incorrectly configured access control security levels.
Who is the vendor for CVE-2026-42412?
The vendor for CVE-2026-42412 is weDevs, the company behind the WP User Frontend plugin.