PT-2026-40554 · Wedevs · User Frontend: Ai Powered Frontend Posting

·

CVE-2026-4058

·

Published

2026-05-12

·

Updated

2026-06-10

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration versions prior to 4.3.3
Description The plugin is subject to unauthorized data modification because the user subscription cancel() function lacks a proper capability check. This allows authenticated attackers with Subscriber-level permissions or higher to cancel subscription packs for any user, including those with administrator privileges.
Recommendations Update to a version later than 4.3.2. As a temporary workaround, restrict access to the user subscription cancel() function to prevent unauthorized subscription cancellations.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4058

Affected Products

User Frontend: Ai Powered Frontend Posting