Skip to content

Known CVE

User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment Deletion

The WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the Frontend_Form_Ajax::submit_post function. This makes it possible for unauthenticated attackers to delete attachment records through the plugin's AJAX handling when a public frontend form is available.

CVE-2025-14047

Medium2025CVSS 5.3CWE-862

cve2025 · wordpress · wp · wp-plugin · user-frontend · wpuf · authorization-bypass · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website