Impact
The WP User Frontend WordPress plugin fails to enforce the subscription purchase requirement in one of its post-creation handlers. Authenticated users with subscriber-level or higher access are allowed to create and, depending on form configuration, immediately publish posts through forms that are meant to be restricted to paying subscribers. This flaw is an access-control weakness that allows malicious or unwanted content to be published under the guise of a legitimate subscriber, potentially leading to defacement, spam, or the distribution of malicious material.
Affected Systems
WP User Frontend plugin versions earlier than 4.3.12. The vulnerability affects any WordPress installation using the plugin with subscription-gated forms, regardless of the specific subscription provider configuration.
Risk and Exploitability
The CVSS score of 4.3 places the flaw at a moderate severity level. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires an authenticated user with at least subscriber privileges and relies on the omission of a subscription-validation check. Because the attack vector is through the normal web interface and the defenses are in place only for higher-level users, the risk of exploitation is non-zero but limited to users who may legitimately have subscriber access.
OpenCVE Enrichment