CVE-2026-79618
Received Received - Intake

Authenticated Post Creation in WP User Frontend Plugin

Vulnerability report for CVE-2026-79618, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_user_frontend wp_user_frontend to 4.3.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WP User Frontend WordPress plugin before version 4.3.12. It allows authenticated users with subscriber-level access or higher to create posts through forms meant for paying subscribers. The plugin fails to enforce subscription requirements in a post-creation handler, potentially allowing immediate publication of these posts depending on form settings.

Detection Guidance

Check the installed version of the WP User Frontend plugin in your WordPress admin panel. If the version is below 4.3.12, the system is vulnerable. Use commands like 'wp plugin list' in WP-CLI or inspect the plugin files for version details.

Impact Analysis

If you use the WP User Frontend plugin with versions prior to 4.3.12, unauthorized users could create and publish posts that should only be accessible to paying subscribers. This could lead to unauthorized content being added to your site, bypassing subscription restrictions and potentially exposing premium content to non-paying users.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR or HIPAA if the unauthorized post creation involves sensitive data. Unauthorized publishing of posts may lead to data exposure or integrity issues, depending on the form's configuration and content.

Mitigation Strategies

Update the WP User Frontend plugin to version 4.3.12 or later immediately. Disable the plugin temporarily if an update is not immediately available. Review user roles and permissions to ensure only authorized users can create posts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79618. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart