CVE-2026-14568
Received Received - Intake

Attachment Deletion Flaw in User Frontend WordPress Plugin

Vulnerability report for CVE-2026-14568, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: WPScan

Description

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_user_frontend wp_user_frontend to 4.3.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-14568 is a vulnerability in the WP User Frontend WordPress plugin versions before 4.3.8. It allows unauthenticated attackers to delete attachments that have no assigned author, such as guest uploads or placeholder media. The plugin fails to verify ownership before deletion, enabling attackers to permanently remove these files from the server.

Detection Guidance

Check if your WP User Frontend plugin version is below 4.3.8. Inspect server logs for unauthorized deletion requests or missing attachments. Use WPScan to scan for vulnerable versions.

Impact Analysis

This vulnerability can lead to data loss if an attacker deletes important attachments like guest uploads or media files. It may disrupt website functionality, cause errors in plugins relying on these files, and compromise user-generated content. Unauthenticated deletion could also affect site integrity and user experience.

Compliance Impact

This vulnerability may impact compliance by allowing unauthorized deletion of user data, which could violate GDPR's data integrity principles or HIPAA's requirements for protecting health information. Unauthorized modifications to data storage could lead to regulatory penalties or loss of certification.

Mitigation Strategies

Update the WP User Frontend plugin to version 4.3.8 or later. Review and restore any deleted attachments from backups. Monitor for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14568. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart