Sceawere
Vulnerability Detail
CVE-2026-79618UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP User Frontend Improper Authorization
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 16h ago
- Vendor
- Unknown
- Product
- WP User Frontend
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-02T07:16:37.873Z",
"pubdate": "2026-10-02T07:16:37.873Z",
"executiveSummary": "The WP User Frontend WordPress plugin, specifically in versions prior to 4.3.12, contains an improper authorization vulnerability within its post-creation handler functionality. This security defect allows authenticated users holding a subscriber-level role or higher to circumvent defined subscription-purchase requirements when interacting with form submissions.\nBy manipulating the request flow, an attacker can successfully create and potentially publish posts via forms specifically restricted to paid subscribers. The impact includes the unauthorized creation of content, which may violate platform policies, bypass monetization models, or be utilized for content spamming or unauthorized information dissemination. Exploitation requires the attacker to possess an authenticated account on the target WordPress installation, specifically with at least subscriber-level privileges. This vulnerability highlights a failure in the plugin's access control enforcement mechanisms during the server-side processing of form data.",
"technicalDetails": "The vulnerability resides in the post-creation handler of the WP User Frontend plugin. The root cause is a deficiency in the server-side access control validation logic, which fails to verify if the authenticated user has satisfied the mandatory subscription-purchase requirement before executing the post-creation process.\nUnder normal operating conditions, WP User Frontend forms configured for 'paying subscribers only' should intercept and deny requests from users who do not hold the required subscription status. However, due to a missing or flawed authorization check in the handler, the request processing routine proceeds to execute the post-creation logic regardless of the user's subscription metadata or payment state.\nThe attack flow begins when an authenticated user (with subscriber-level access) identifies a post-submission form configured with subscription restrictions. The attacker submits the form payload to the endpoint handling the POST request. Because the server-side handler fails to perform an adequate check against the user's role or subscription status, the application accepts the submitted content. Depending on the specific configuration of the form—such as an 'auto-publish' or 'immediate-publish' setting—the post is successfully created and becomes live on the site, effectively bypassing the intended business logic constraints.\nThe vulnerability is limited to authenticated users; it does not allow unauthenticated access to the restricted forms. However, the requirement for only subscriber-level privileges significantly widens the potential threat actor base on sites with open registration. The post-exploitation impact includes the ability for malicious or unauthorized users to influence the site's content, bypass paywalls, and potentially gain visibility in search engines or public feeds for content that should have required a valid subscription.\nAffected versions are strictly those prior to 4.3.12. The issue exists within the logic responsible for processing form-submitted post data, where the plugin attempts to facilitate post creation without confirming that the user meets the subscription prerequisites established for the specific form being utilized."
}