PT-2026-40554 · Wedevs · User Frontend: Ai Powered Frontend Posting
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration versions prior to 4.3.3
Description
The plugin is subject to unauthorized data modification because the
user subscription cancel() function lacks a proper capability check. This allows authenticated attackers with Subscriber-level permissions or higher to cancel subscription packs for any user, including those with administrator privileges.Recommendations
Update to a version later than 4.3.2.
As a temporary workaround, restrict access to the
user subscription cancel() function to prevent unauthorized subscription cancellations.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
User Frontend: Ai Powered Frontend Posting