Junglewise Threat Intelligence

CVE-2026-12418: wedevs WP User Frontend IDOR in wpuf_files_data

CVE-2026-12418 · Severity: medium · CVSS 5.3 · Published 2026-07-09

Technologies: weDevs WP User Frontend. Vendors: weDevs.

Executive brief

A vulnerability in the WP User Frontend plugin for WordPress allows unauthorized individuals to modify existing website content. By exploiting a flaw in how the plugin handles post submissions, an attacker can overwrite the titles and text of any post or page, including those created by administrators. This could lead to website defacement or the spread of misinformation.

Technical details

The WP User Frontend plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) via the 'wpuf_files_data' parameter in versions up to and including 4.3.7. This vulnerability stems from missing validation on a user-controlled key within the 'wpuf_submit_post' AJAX action. Although the action is protected by a nonce, it lacks a capability check for the downstream post-edit operation. An unauthenticated attacker with access to any WPUF post submission form can exploit this to overwrite the post_title, post_content, and post_excerpt of arbitrary posts, including those authored by administrators.

Affected products

  • wedevs WP User Frontend <= 4.3.7

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory

References

Related threats