PT-2026-1602 · WordPress · Wp Front User Submit
CVE-2025-13419
·
Publicado
2026-01-07
·
Atualizado
2026-01-07
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Front User Submit plugin for WordPress versions up to and including 5.0.0
Description
The plugin is susceptible to unauthorized data modification because of a missing capability check on the
/wp-json/bfe/v1/revert API endpoint. This allows unauthenticated attackers to delete arbitrary media attachments. The affected API endpoint is /wp-json/bfe/v1/revert.Recommendations
Update the WP Front User Submit plugin to a version later than 5.0.0.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wp Front User Submit