CVE-2026-5127
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration
Minimum safe version
4.3.2
Update to 4.3.2 or later to address 23 fixable vulnerabilities
CVE-2026-42412
WP User Frontend <= 4.1.12 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Authenticated (Author+) Arbitrary File Upload
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter
CVE-2026-32485
CVE-2026-24364
CVE-2025-14047
WordPress WP User Frontend Plugin <= 4.1.12 is vulnerable to Broken Access Control
CVE-2024-38693
WordPress WP User Frontend Plugin <= 4.0.7 is vulnerable to Backdoor
Various Plugins <= Various Version - Use of Polyfill.io
CVE-2023-47682
CVE-2023-45002
WP User Frontend <= 2.3.10 - Unrestricted File Upload
WP User Frontend < 3.5.25 - Admin+ SQL Injection
WordPress WP User Frontend Plugin <= 3.6.0 is vulnerable to Cross Site Request Forgery (CSRF)
WP User Frontend < 2.3.11 - Arbitrary File Upload
WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress < 3.5.25 - Authenticated (Admin+) SQL Injection
CVE-2021-24649
WordPress WP User Frontend Plugin 2.3.10 - Unrestricted File Upload
WordPress WP User Frontend plugin <= 3.5.23 - SQL Injection (SQLi) vulnerability
CVE-2021-25076