CVE-2026-95523: WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability
Published Sep 23, 2026
·Updated
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Affected Software
1 affected component
WordPress WP User Frontend<=4.3.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.3.12
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Subscriber-level access to a WordPress site using WP User Frontend 4.3.11 or earlier. The provided data does not indicate that unauthenticated visitors can exploit it.
2
What security impact does successful exploitation have?
The issue can compromise integrity, as reflected by the CVSS vector’s I:H rating. The provided information does not identify the specific actions or data that can be altered.
3
Are confidentiality or availability affected?
The supplied CVSS vector rates confidentiality and availability impact as none. The documented impact is limited to integrity.