WordPress Plugin Vulnerabilities

WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form

Description

The plugin does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.

Proof of Concept

Affects Plugins

Fixed in 4.3.11

References

Miscellaneous

Original Researcher
Charles Vosburgh
Submitter
Charles Vosburgh
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 2 days ago)
Last Updated
2026-08-31 (about 2 days ago)

Other