PT-2026-56401 · WordPress · Wp User Frontend
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration versions prior to 4.3.2
Description
An Insecure Direct Object Reference (IDOR) exists in the
payment page() function. This issue occurs because of missing validation on the user id variable, which is controlled by the user. Unauthenticated attackers can exploit this to activate a free subscription pack for any user on the site, which overwrites existing paid subscriptions and results in the loss of paid features.Recommendations
Update User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration to version 4.3.2 or later.
As a temporary workaround, restrict access to the
payment page() function until the update is applied.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp User Frontend