Impact
Missing authorization checks in the weDevs WP User Frontend plugin allow attackers to bypass normal access controls, enabling them to perform privileged actions such as creating, editing, or deleting content that should be restricted. This flaw is classified as CWE‑862 and could lead to unauthorized content manipulation if exploited.
Affected Systems
The weDevs WP User Frontend plugin for WordPress, any version up to and including 4.3.1, is affected.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity; EPSS is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation to date. Based on the description, it is inferred that the flaw may be exploitable via the plugin’s web interface from a remote client, though no explicit authentication requirements or attack surface were detailed in the input.
OpenCVE Enrichment