Executive brief
A vulnerability in the WP User Frontend plugin for WordPress allows unauthorized individuals to modify existing website content. By exploiting a flaw in how the plugin handles post submissions, an attacker can overwrite the titles and text of any post or page, including those created by administrators. This could lead to website defacement or the spread of misinformation.
Technical details
The WP User Frontend plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) via the 'wpuf_files_data' parameter in versions up to and including 4.3.7. This vulnerability stems from missing validation on a user-controlled key within the 'wpuf_submit_post' AJAX action. Although the action is protected by a nonce, it lacks a capability check for the downstream post-edit operation. An unauthenticated attacker with access to any WPUF post submission form can exploit this to overwrite the post_title, post_content, and post_excerpt of arbitrary posts, including those authored by administrators.
Affected products
- wedevs WP User Frontend <= 4.3.7
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory
References
- https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.1/includes/Ajax/Frontend_Form_Ajax.php
- https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.1/includes/Traits/FieldableTrait.php
- https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.1/includes/Traits/FieldableTrait.php
- https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.6/includes/Ajax/Frontend_Form_Ajax.php
- https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.6/includes/Traits/FieldableTrait.php
- https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.6/includes/Traits/FieldableTrait.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3578622%40wp-user-frontend&new=3578622%40wp-user-frontend