GHSA-5f7g-qp7c-jr44MediumCVSS 4.3

The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase...

Published
October 2, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.

🔗 References (3)