{"schema_version":1,"title":"weDevs WP User Frontend vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in weDevs WP User Frontend: 3 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-95525, was published on 23 September 2026.","url":"https://junglewise.ai/threats/technologies/user-frontend","json_url":"https://junglewise.ai/threats/technologies/user-frontend.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/user-frontend","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":13,"critical":0,"exploited":0,"last_7_days":3,"last_30_days":7,"last_90_days":12,"last_365_days":13},"latest":[{"cve":"CVE-2026-95525","cvss":6.5,"epss":0.0047,"slug":"cve-2026-95525-subscriber-arbitrary-file-deletion-in-wp-user-frontend-4-3-11","title":"WP User Frontend arbitrary file deletion","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:51.813+00:00","url":"https://junglewise.ai/threats/cve-2026-95525-subscriber-arbitrary-file-deletion-in-wp-user-frontend-4-3-11"},{"cve":"CVE-2026-95524","cvss":5.3,"epss":0.0025,"slug":"cve-2026-95524-unauthenticated-bypass-vulnerability-in-wp-user-frontend-4-3-11","title":"WP User Frontend authentication bypass","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:51.67+00:00","url":"https://junglewise.ai/threats/cve-2026-95524-unauthenticated-bypass-vulnerability-in-wp-user-frontend-4-3-11"},{"cve":"CVE-2026-95523","cvss":6.5,"epss":0.0034,"slug":"cve-2026-95523-subscriber-bypass-vulnerability-in-wp-user-frontend-4-3-11","title":"WP User Frontend subscriber privilege bypass","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:51.527+00:00","url":"https://junglewise.ai/threats/cve-2026-95523-subscriber-bypass-vulnerability-in-wp-user-frontend-4-3-11"},{"cve":"CVE-2026-17563","cvss":5.3,"epss":0.0022,"slug":"cve-2026-17563-wordpress-user-frontend-unauthenticated-post-creation-via","title":"WordPress User Frontend unauthenticated post creation via subscription bypass","severity":"medium","exploited":false,"published_at":"2026-09-02T15:17:37.717+00:00","url":"https://junglewise.ai/threats/cve-2026-17563-wordpress-user-frontend-unauthenticated-post-creation-via"},{"cve":"CVE-2026-81283","cvss":8.8,"epss":0.0052,"slug":"cve-2026-81283-wp-user-frontend-php-object-injection-vulnerability","title":"WP User Frontend PHP object injection vulnerability","severity":"high","exploited":false,"published_at":"2026-09-02T12:17:12.267+00:00","url":"https://junglewise.ai/threats/cve-2026-81283-wp-user-frontend-php-object-injection-vulnerability"},{"cve":"CVE-2026-14567","cvss":5.3,"epss":0.0025,"slug":"cve-2026-14567-wordpress-wp-user-frontend-information-disclosure-in-user","title":"WordPress WP User Frontend information disclosure in user directory search","severity":"medium","exploited":false,"published_at":"2026-08-28T08:16:40.423+00:00","url":"https://junglewise.ai/threats/cve-2026-14567-wordpress-wp-user-frontend-information-disclosure-in-user"},{"cve":"CVE-2026-14558","cvss":7.2,"epss":0.0052,"slug":"cve-2026-14558-wordpress-user-frontend-php-object-injection-in-form-builder","title":"WordPress User Frontend PHP object injection in form builder","severity":"high","exploited":false,"published_at":"2026-08-28T08:16:40.327+00:00","url":"https://junglewise.ai/threats/cve-2026-14558-wordpress-user-frontend-php-object-injection-in-form-builder"},{"cve":"CVE-2026-14568","cvss":6.5,"slug":"cve-2026-14568-wp-user-frontend-unauthenticated-attachment-deletion","title":"WP User Frontend unauthenticated attachment deletion","severity":"info","exploited":false,"published_at":"2026-07-27T07:16:25.987+00:00","url":"https://junglewise.ai/threats/cve-2026-14568-wp-user-frontend-unauthenticated-attachment-deletion"},{"cve":"CVE-2026-12418","cvss":5.3,"slug":"cve-2026-12418-wedevs-wp-user-frontend-idor-in-wpuf-files-data","title":"wedevs WP User Frontend IDOR in wpuf_files_data","severity":"medium","exploited":false,"published_at":"2026-07-09T08:16:46+00:00","url":"https://junglewise.ai/threats/cve-2026-12418-wedevs-wp-user-frontend-idor-in-wpuf-files-data"},{"cve":"CVE-2026-12406","cvss":5.3,"slug":"cve-2026-12406-wedevs-user-frontend-authorization-bypass-in-wpuf-file-del-ajax","title":"wedevs User Frontend authorization bypass in wpuf_file_del AJAX action","severity":"medium","exploited":false,"published_at":"2026-07-09T08:16:45.85+00:00","url":"https://junglewise.ai/threats/cve-2026-12406-wedevs-user-frontend-authorization-bypass-in-wpuf-file-del-ajax"},{"cve":"CVE-2026-5459","cvss":5.3,"slug":"cve-2026-5459-wedevs-wp-user-frontend-idor-in-payment-page-function","title":"weDevs WP User Frontend IDOR in payment_page function","severity":"medium","exploited":false,"published_at":"2026-07-08T13:16:56.887+00:00","url":"https://junglewise.ai/threats/cve-2026-5459-wedevs-wp-user-frontend-idor-in-payment-page-function"},{"cve":"CVE-2026-57334","cvss":6.5,"slug":"cve-2026-57334-wedevs-wp-user-frontend-broken-access-control","title":"weDevs WP User Frontend broken access control","severity":"medium","exploited":false,"published_at":"2026-06-29T15:16:43.72+00:00","url":"https://junglewise.ai/threats/cve-2026-57334-wedevs-wp-user-frontend-broken-access-control"},{"cve":"CVE-2026-4058","cvss":4.3,"slug":"cve-2026-4058-wp-user-frontend-missing-authorization-in-user-subscription-cancel","title":"WP User Frontend missing authorization in user_subscription_cancel","severity":"medium","exploited":false,"published_at":"2026-06-09T10:16:44.557+00:00","url":"https://junglewise.ai/threats/cve-2026-4058-wp-user-frontend-missing-authorization-in-user-subscription-cancel"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":3}],"related":[{"name":"weDevs Dokan Pro","slug":"dokan-pro","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/dokan-pro"},{"name":"weDevs Dokan","slug":"dokan","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/dokan"},{"name":"weDevs weDocs","slug":"wedocs","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/wedocs"},{"name":"weDevs WP Project Manager","slug":"wp-project-manager","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/wp-project-manager"},{"name":"weDevs StoreGrowth","slug":"storegrowth","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/storegrowth"}],"technology":{"hub":true,"name":"weDevs WP User Frontend","slug":"user-frontend","vendor":{"name":"weDevs","slug":"wedevs","url":"https://junglewise.ai/threats/vendors/wedevs"},"aliases":["wp-user-frontend"],"category":"library","homepage":"https://wedevs.com/wp-user-frontend-pro/","repo_url":"https://github.com/weDevsOfficial/wp-user-frontend","description":"WP User Frontend is a WordPress plugin that allows users to manage posts, profiles, and registrations from the site frontend.","url":"https://junglewise.ai/threats/technologies/user-frontend"},"most_severe":[{"cve":"CVE-2026-81283","cvss":8.8,"epss":0.0052,"slug":"cve-2026-81283-wp-user-frontend-php-object-injection-vulnerability","title":"WP User Frontend PHP object injection vulnerability","severity":"high","exploited":false,"published_at":"2026-09-02T12:17:12.267+00:00","url":"https://junglewise.ai/threats/cve-2026-81283-wp-user-frontend-php-object-injection-vulnerability"},{"cve":"CVE-2026-14558","cvss":7.2,"epss":0.0052,"slug":"cve-2026-14558-wordpress-user-frontend-php-object-injection-in-form-builder","title":"WordPress User Frontend PHP object injection in form builder","severity":"high","exploited":false,"published_at":"2026-08-28T08:16:40.327+00:00","url":"https://junglewise.ai/threats/cve-2026-14558-wordpress-user-frontend-php-object-injection-in-form-builder"},{"cve":"CVE-2026-95525","cvss":6.5,"epss":0.0047,"slug":"cve-2026-95525-subscriber-arbitrary-file-deletion-in-wp-user-frontend-4-3-11","title":"WP User Frontend arbitrary file deletion","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:51.813+00:00","url":"https://junglewise.ai/threats/cve-2026-95525-subscriber-arbitrary-file-deletion-in-wp-user-frontend-4-3-11"},{"cve":"CVE-2026-95523","cvss":6.5,"epss":0.0034,"slug":"cve-2026-95523-subscriber-bypass-vulnerability-in-wp-user-frontend-4-3-11","title":"WP User Frontend subscriber privilege bypass","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:51.527+00:00","url":"https://junglewise.ai/threats/cve-2026-95523-subscriber-bypass-vulnerability-in-wp-user-frontend-4-3-11"},{"cve":"CVE-2026-57334","cvss":6.5,"slug":"cve-2026-57334-wedevs-wp-user-frontend-broken-access-control","title":"weDevs WP User Frontend broken access control","severity":"medium","exploited":false,"published_at":"2026-06-29T15:16:43.72+00:00","url":"https://junglewise.ai/threats/cve-2026-57334-wedevs-wp-user-frontend-broken-access-control"},{"cve":"CVE-2026-95524","cvss":5.3,"epss":0.0025,"slug":"cve-2026-95524-unauthenticated-bypass-vulnerability-in-wp-user-frontend-4-3-11","title":"WP User Frontend authentication bypass","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:51.67+00:00","url":"https://junglewise.ai/threats/cve-2026-95524-unauthenticated-bypass-vulnerability-in-wp-user-frontend-4-3-11"},{"cve":"CVE-2026-14567","cvss":5.3,"epss":0.0025,"slug":"cve-2026-14567-wordpress-wp-user-frontend-information-disclosure-in-user","title":"WordPress WP User Frontend information disclosure in user directory search","severity":"medium","exploited":false,"published_at":"2026-08-28T08:16:40.423+00:00","url":"https://junglewise.ai/threats/cve-2026-14567-wordpress-wp-user-frontend-information-disclosure-in-user"},{"cve":"CVE-2026-17563","cvss":5.3,"epss":0.0022,"slug":"cve-2026-17563-wordpress-user-frontend-unauthenticated-post-creation-via","title":"WordPress User Frontend unauthenticated post creation via subscription bypass","severity":"medium","exploited":false,"published_at":"2026-09-02T15:17:37.717+00:00","url":"https://junglewise.ai/threats/cve-2026-17563-wordpress-user-frontend-unauthenticated-post-creation-via"},{"cve":"CVE-2026-12418","cvss":5.3,"slug":"cve-2026-12418-wedevs-wp-user-frontend-idor-in-wpuf-files-data","title":"wedevs WP User Frontend IDOR in wpuf_files_data","severity":"medium","exploited":false,"published_at":"2026-07-09T08:16:46+00:00","url":"https://junglewise.ai/threats/cve-2026-12418-wedevs-wp-user-frontend-idor-in-wpuf-files-data"},{"cve":"CVE-2026-12406","cvss":5.3,"slug":"cve-2026-12406-wedevs-user-frontend-authorization-bypass-in-wpuf-file-del-ajax","title":"wedevs User Frontend authorization bypass in wpuf_file_del AJAX action","severity":"medium","exploited":false,"published_at":"2026-07-09T08:16:45.85+00:00","url":"https://junglewise.ai/threats/cve-2026-12406-wedevs-user-frontend-authorization-bypass-in-wpuf-file-del-ajax"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}