Known CVE
User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment Deletion
The WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the Frontend_Form_Ajax::submit_post function. This makes it possible for unauthenticated attackers to delete attachment records through the plugin's AJAX handling when a public frontend form is available.
CVE-2025-14047
Medium2025CVSS 5.3CWE-862
cve2025 · wordpress · wp · wp-plugin · user-frontend · wpuf · authorization-bypass · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website