Plugin Vulnerability Hub
Plugin 17 known issues Latest disclosed Jun 08, 2026

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Vulnerabilities

Review known vulnerability records for the WordPress plugin User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration (`wp-user-frontend`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-4058, CVE-2026-5127 and CVE-2026-42412, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
17
High or Critical
8
Patch Coverage
100%
Last Updated
Jun 08, 2026
Related Security Guides

Use these guides while reviewing User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
17
1. Match the Package
Confirm the installed WordPress plugin slug is wp-user-frontend before acting on any CVE from this cluster.
2. Sort by Severity
Start with 8 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
17 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
15
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2024-38693
WP User Frontend <= 4.0.7 - Authenticated (Administrator+) SQL Injection
SQL Injection Versions up to 4.0.7 4.0.8 CVSS 9.1
CVE-2026-5127
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & Us...
Vulnerability Versions up to 4.3.1 4.3.2 CVSS 8.8
CVE-2026-1565
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & Us...
Remote Code Execution Versions up to 4.2.8 4.2.9 CVSS 8.8
CVE-2023-47682
WP User Frontend <= 3.6.5 - Authenticated (Author+) Privilege Escalation
Privilege Escalation Versions up to 3.6.5 3.6.6 CVSS 8.8
CVE-2021-25076
WP User Frontend <= 3.5.25 - SQL Injection & Reflected Cross-Site Scripting
SQL Injection Versions up to 3.5.25 3.5.26 CVSS 8.8
CVE-2021-24649
WP User Frontend <= 3.5.28 - Privilege Escalation
Privilege Escalation Versions up to 3.5.28 3.5.29 CVSS 8.1
CVE-2025-58672
WP User Frontend <= 4.1.12 - Missing Authorization
Vulnerability Versions up to 4.1.12 4.1.13 CVSS 5.4
CVE-2025-58673
WP User Frontend <= 4.1.12 - Authenticated (Subscriber+) Arbitrary Shortcode Executi...
Vulnerability Versions up to 4.1.12 4.1.13 CVSS 5.4
CVE-2024-38693 Critical 4.0.8
CVE-2024-38693 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration SQL Injection

WP User Frontend <= 4.0.7 - Authenticated (Administrator+) SQL Injection

CVE-2026-5127 High 4.3.2
CVE-2026-5127 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Vulnerability

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection

CVE-2026-1565 High 4.2.9
CVE-2026-1565 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Remote Code Execution

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Authenticated (Author+) Arbitrary File Upload

CVE-2023-47682 High 3.6.6
CVE-2023-47682 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Privilege Escalation

WP User Frontend <= 3.6.5 - Authenticated (Author+) Privilege Escalation

CVE-2021-25076 High 3.5.26
CVE-2021-25076 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration SQL Injection

WP User Frontend <= 3.5.25 - SQL Injection & Reflected Cross-Site Scripting

CVE-2021-24649 High 3.5.29
CVE-2021-24649 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Privilege Escalation

WP User Frontend <= 3.5.28 - Privilege Escalation

CVE-2025-58672 Medium 4.1.13
CVE-2025-58672 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Vulnerability

WP User Frontend <= 4.1.12 - Missing Authorization

CVE-2025-58673 Medium 4.1.13
CVE-2025-58673 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Vulnerability

WP User Frontend <= 4.1.12 - Authenticated (Subscriber+) Arbitrary Shortcode Execution

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
17 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
2 critical and 6 high severity findings.
Recent CVEs
CVE-2026-4058, CVE-2026-5127 and CVE-2026-42412
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2026-4058 Medium Patch path listed

CVE-2026-4058: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...

Published
Jun 08, 2026
Patch Status
4.3.3
Known Vulnerabilities

Reports for User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-4058
CVE-2026-4058: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and...

Published
Jun 08, 2026
Patched Release
4.3.3
Affected Versions
Versions up to 4.3.2
Next Step
Update to 4.3.3 or newer if supported.
Plugin High Patched: Yes CVE-2026-5127
CVE-2026-5127: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking o...

Published
May 07, 2026
Patched Release
4.3.2
Affected Versions
Versions up to 4.3.1
Next Step
Update to 4.3.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-42412
CVE-2026-42412: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Missing Authorization

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.1. This makes it possible for un...

Published
Apr 27, 2026
Patched Release
4.3.2
Affected Versions
Versions up to 4.3.1
Next Step
Update to 4.3.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-32485
CVE-2026-32485: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.8. This makes it possible fo...

Published
Mar 23, 2026
Patched Release
4.2.9
Affected Versions
Versions up to 4.2.8
Next Step
Update to 4.2.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-2233
CVE-2026-2233: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2...

Published
Mar 14, 2026
Patched Release
4.2.9
Affected Versions
Versions up to 4.2.8
Next Step
Update to 4.2.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24364
CVE-2026-24364: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.5 - Missing Authorization

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.5. This makes it possible fo...

Published
Mar 10, 2026
Patched Release
4.2.6
Affected Versions
Versions up to 4.2.5
Next Step
Update to 4.2.6 or newer if supported.
Plugin High Patched: Yes CVE-2026-1565
CVE-2026-1565: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Authenticated (Author+) Arbitrary File Upload

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Adm...

Published
Feb 26, 2026
Patched Release
4.2.9
Affected Versions
Versions up to 4.2.8
Next Step
Update to 4.2.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14047
CVE-2025-14047: WP User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in...

Published
Jan 01, 2026
Patched Release
4.2.5
Affected Versions
Versions up to 4.2.4
Next Step
Update to 4.2.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-58672
CVE-2025-58672: WP User Frontend <= 4.1.12 - Missing Authorization

The WP User Frontend plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unaut...

Published
Sep 22, 2025
Patched Release
4.1.13
Affected Versions
Versions up to 4.1.12
Next Step
Update to 4.1.13 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-58673
CVE-2025-58673: WP User Frontend <= 4.1.12 - Authenticated (Subscriber+) Arbitrary Shortcode Execution

The The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.1.12. This is due to the software allow...

Published
Sep 22, 2025
Patched Release
4.1.13
Affected Versions
Versions up to 4.1.12
Next Step
Update to 4.1.13 or newer if supported.
Plugin Critical Patched: Yes CVE-2024-38693
CVE-2024-38693: WP User Frontend <= 4.0.7 - Authenticated (Administrator+) SQL Injection

The WP User Frontend plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 4.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Published
Aug 01, 2024
Patched Release
4.0.8
Affected Versions
Versions up to 4.0.7
Next Step
Update to 4.0.8 or newer if supported.
Plugin High Patched: Yes CVE-2023-47682
CVE-2023-47682: WP User Frontend <= 3.6.5 - Authenticated (Author+) Privilege Escalation

The WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.5. This is due to the plugin not providing...

Published
Nov 09, 2023
Patched Release
3.6.6
Affected Versions
Versions up to 3.6.5
Next Step
Update to 3.6.6 or newer if supported.