User Frontend

WordPress plugin · user-frontend · WordPress.org ↗
0
Critical
2
High
4
Known total
0
Unfixed
Running User Frontend on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 8.8
WP User Frontend < 4.3.11 - Subscriber+ PHP Object Injection via Frontend Post Edit Form
CVE.org
>=0, <4.3.11 v4.3.11 CVE-2026-19116 Sep 2, 2026
HIGH
CVSS 7.2
WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder
CVE.org
>=0, <4.3.10 v4.3.10 CVE-2026-14558 Aug 28, 2026
MEDIUM
CVSS 5.3
WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form
CVE.org
>=0, <4.3.11 v4.3.11 CVE-2026-17563 Sep 2, 2026
MEDIUM
CVSS 5.3
WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Directory
CVE.org
>=4.3.0, <4.3.10 v4.3.10 CVE-2026-14567 Aug 28, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.