WordPress Plugin Vulnerabilities

WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion

Description

The plugin does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and plugin-installed placeholder media.

Proof of Concept

Affects Plugins

Fixed in 4.3.8

References

Classification

Miscellaneous

Original Researcher
kimsunghoon
Submitter
kimsunghoon
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-07-06 (about 21 days ago)
Added
2026-07-06 (about 20 days ago)
Last Updated
2026-07-06 (about 20 days ago)

Other