Impact
The WordPress plugin User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration suffers from a missing capability check on the user_subscription_cancel() function. This omission allows any authenticated user with Subscriber-level access or higher to cancel any other user's subscription pack, including administrators, thereby causing loss of paid services or subscription benefits. The flaw is a classic example of unauthorized data modification.
Affected Systems
The vulnerability applies to the WeDevs plugin titled User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration in all releases up to and including version 4.3.2. Systems running WordPress with any of these plugin versions are susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Because the EPSS score is not available, exploitation likelihood cannot be precisely quantified, and the issue is not listed in the CISA KEV catalog. The attack vector is authenticated; an attacker only needs to log in with a Subscriber- or higher-level role and then invoke the uncapped cancellation function. Once the vulnerability is known, the exploit is straightforward for legitimate users, making the risk material for organizations that rely on subscription revenue and where role-based access is not tightly controlled.
OpenCVE Enrichment