Junglewise Threat Intelligence

CVE-2026-14568: WP User Frontend unauthenticated attachment deletion

CVE-2026-14568 · Severity: info · CVSS 6.5 · Published 2026-07-27

Technologies: weDevs WP User Frontend. Vendors: Unknown, weDevs.

Executive brief

A vulnerability in the WP User Frontend plugin for WordPress allows unauthorized individuals to delete certain media files from a website. This affects files that do not have a specific owner assigned, such as images uploaded by guests or default placeholder images used by the site. An attacker could use this to disrupt site operations or remove important visual content without needing to log in.

Technical details

The vulnerability exists in the 'wpuf_file_del' AJAX action due to insufficient authorization checks. An unauthenticated attacker can obtain a valid nonce from public plugin pages (such as registration or profile forms) and send a crafted POST request to 'admin-ajax.php' specifying an 'attach_id'. If the target attachment has no assigned author (post_author=0), such as guest uploads or system placeholders, the plugin will permanently delete both the database record and the physical file. This issue is resolved in version 4.3.8.

Affected products

  • Unknown WP User Frontend < 4.3.8

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: advisory
  • 2026-07-27: patched: NVD publication date; fix available in 4.3.8

References

Related threats