Impact
The WordPress plugin User Frontend before version 4.3.11 fails to enforce subscription‑purchase checks when processing frontend post submissions, only performing the check when rendering the form. This oversight allows unauthenticated users to submit posts via forms that are intended for paying subscribers. Depending on the form configuration, the submitted content can be published immediately, giving attackers a channel for spam, defacement, or malicious content.
Affected Systems
This vulnerability affects installations of the User Frontend plugin version 4.3.11 or older. Site operators who have subscription‑audited forms enabled are directly impacted. No specific vendor or system other than WordPress sites running the plugin before the mentioned version are susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. Exploitation requires only access to the vulnerable form endpoint, which is publicly accessible. The lack of an EPSS score and exclusion from the KEV catalog suggest that no widespread exploitation has been documented yet, but the straightforward nature of the attack means that sites could be compromised quickly. Attackers can submit arbitrary post content; if the form is set to auto‑publish, the content appears immediately on the site, allowing for defacement or spam.
OpenCVE Enrichment