Extension WordPress
Vulnérabilités User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration
Cette page rassemble les failles publiées pour User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration
24 fiches
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 – Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to…
*-4.3.7
4.3.8
08/07/2026
User Frontend <= 4.3.7 – Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.7. This is due to the plugin not properly…
*-4.3.7
4.3.8
08/07/2026
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 – Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to…
*-4.3.1
4.3.2
08/07/2026
User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration <= 4.3.7 – Missing Authorization
The User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including,…
*-4.3.7
4.3.8
29/06/2026
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 – Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up…
*-4.3.2
4.3.3
08/06/2026
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 – Authenticated (Subscriber+) PHP Object Injection
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation…
*-4.3.1
4.3.2
07/05/2026
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 – Missing Authorization
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.1.…
*-4.3.1
4.3.2
27/04/2026
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 – Missing Authorization
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…
*-4.2.8
4.2.9
23/03/2026
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 – Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up…
*-4.2.8
4.2.9
14/03/2026
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.5 – Missing Authorization
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…
*-4.2.5
4.2.6
10/03/2026
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 – Authenticated (Author+) Arbitrary File Upload
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function…
*-4.2.8
4.2.9
26/02/2026
WP User Frontend <= 4.2.4 – Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in…
*-4.2.4
4.2.5
01/01/2026
WP User Frontend <= 4.1.12 – Missing Authorization
The WP User Frontend plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.12. This makes it possible for authenticated attackers, with subscriber-level access…
*-4.1.12
4.1.13
22/09/2025
WP User Frontend <= 4.1.12 – Authenticated (Subscriber+) Arbitrary Shortcode Execution
The The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.1.12. This is due…
*-4.1.12
4.1.13
22/09/2025
WP User Frontend <= 4.0.7 – Authenticated (Administrator+) SQL Injection
The WP User Frontend plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 4.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-4.0.7
4.0.8
01/08/2024
Various Plugins <= Various Version – Use of Polyfill.io
Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Polyfill.io. Polyfill.io is a JavaScript library used to streamline delivery of content across older browsers and was taken over…
*-4.0.7
4.0.8
25/06/2024
WP User Frontend <= 3.6.5 – Authenticated (Author+) Privilege Escalation
The WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.5. This is due to…
*-3.6.5
3.6.6
09/11/2023
WP User Frontend <= 3.6.8 – Missing Authorization via AJAX actions
The WP User Frontend plugin for WordPress is vulnerable to unauthorized functionality use due to a missing capability check on several functions corresponding to AJAX actions in versions up to, and including, 3.6.8. This makes it possible for…
*-3.6.8
3.6.9
03/10/2023
Appsero <= 1.2.1 – Missing Authorization
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…
*-3.6.0
3.6.1
16/12/2022
Appsero <= 1.2.0 – Cross-Site Request Forgery
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…
*-3.6.0
3.6.1
14/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.