CVE-2026-79618: WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP User Frontend WordPress pluginto a version that resolves this vulnerability.Fixed in 4.3.12
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with subscriber-level access or higher can exploit it. Unauthenticated visitors are not described as able to use the affected handler.
What is required for exploitation?
The attacker needs an account with at least subscriber privileges and access to a subscription-gated post-creation form. No user interaction is required.
Can the created content become public immediately?
Potentially. Whether posts are immediately published depends on the affected form's configuration; otherwise, the issue still allows unauthorized post creation through forms intended for paying subscribers.
How can I determine whether my site is affected?
Sites using weDevs WP User Frontend versions earlier than 4.3.12 are affected if they use subscription-gated post-creation forms. Review those forms' publication settings to determine whether unauthorized submissions could be published immediately.