Description
The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including, 4.2.4. This makes it possible for unauthenticated attackers to delete attachment.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Fri, 02 Jan 2026 02:30:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:59:43.442Z
Reserved: 2025-12-04T16:37:13.476Z
Link: CVE-2025-14047
Updated: 2026-01-05T20:32:35.839Z
Status : Deferred
Published: 2026-01-02T03:15:50.757
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-14047
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:14:16Z
Weaknesses