CVE-2026-14568 PUBLISHED

WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion

Assigner: WPScan
Reserved: 03.07.2026 Published: 27.07.2026 Updated: 27.07.2026

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media.

Product Status

Vendor Unknown
Product User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration
Versions Default: unaffected
  • affected from 0 to 4.3.8 (excl.)

Credits

  • kimsunghoon finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE