CVE-2026-95524: WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability
Published Sep 23, 2026
·Updated
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Affected Software
1 affected component
WordPress WP User Frontend<=4.3.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP User Frontend pluginto a version that resolves this vulnerability.Fixed in 4.3.12
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit it.
2
Which installations are affected?
WP User Frontend versions 4.3.11 and earlier are identified as affected. The provided information does not state whether a particular plugin configuration is required.
3
What is the reported impact?
The reported CVSS vector indicates low integrity impact and no reported confidentiality or availability impact. Exploitation is network-accessible, requires low attack complexity, and requires no user interaction.