CVE-2026-95525: WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability
Published Sep 23, 2026
·Updated
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
Affected Software
1 affected component
weDevs WP User Frontend<=4.3.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP User Frontend pluginto a version that resolves this vulnerability.Fixed in 4.3.12
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user with Subscriber-level access can exploit the vulnerability. No user interaction is required.
2
What is the likely impact of successful exploitation?
Successful exploitation can cause arbitrary file deletion, resulting in a high availability impact. The supplied severity vector indicates no confidentiality or integrity impact.
3
Are installations running version 4.3.11 affected?
Yes. The affected version range includes WP User Frontend 4.3.11 and earlier.