Junglewise Threat Intelligence

CVE-2026-57334: weDevs WP User Frontend broken access control

CVE-2026-57334 · Severity: medium · CVSS 6.5 · Published 2026-06-29

Technologies: weDevs WP User Frontend. Vendors: weDevs.

Executive brief

WP User Frontend is a WordPress plugin that allows users to create profiles and submit content from the front-end of a website. A security flaw in versions 4.3.7 and earlier allows unauthenticated visitors to perform actions they should not be authorized to do. This could lead to unauthorized modifications of site content or settings, potentially impacting the integrity of the website.

Technical details

The WP User Frontend plugin for WordPress is vulnerable to broken access control due to missing authorization (CWE-862) in versions up to and including 4.3.7. This vulnerability allows an unauthenticated remote attacker to bypass intended access restrictions and execute functions that should be restricted to higher-privileged users. The flaw stems from a lack of proper validation of user permissions or nonce tokens. Attackers can exploit this over the network without any user interaction. A fix is available in version 4.3.8.

Affected products

  • weDevs WP User Frontend <= 4.3.7

Timeline

  • 2026-04-19: other: Vulnerability reported by researcher Tiago Ventura
  • 2026-06-29: disclosed: Vulnerability published by Patchstack and NVD
  • 2026-06-29: patched: Version 4.3.8 released to address the issue

References

Related threats