← Back to CVE search

CVE-2026-42412

weDevs WP User Frontend

Description

Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.

CVSS 6.5EPSS 0.19499999999999998%Risk 0.66
View source
Published
2026-04-29 09:16:24
Affected versions
<=4.3.1
Type
Installed app
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L