Impact
A missing ownership check in the User Frontend plugin before version 4.3.8 lets attackers delete media attachments that are not assigned to an author, including guest uploads or placeholder images. The flaw permits complete removal of those files, causing loss of content and representing a denial‑of‑service risk to the website’s media resources. The weakness falls under authentication bypass (CWE‑287).
Affected Systems
WordPress sites running the User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration plugin at any release prior to 4.3.8 are impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability that can be exploited without authentication. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, but any publicly reachable site with the vulnerable plugin can delete non‑owned attachments directly. The lack of required credentials makes this a high‑impact attack vector for sites that allow guest uploads or host placeholder media.
OpenCVE Enrichment