Impact
The WP User Frontend plugin through version 4.3.11 suffers an unauthenticated bypass that allows attackers to access plugin functionality normally protected by authentication checks. This flaw, identified as CWE-290, could enable an attacker to submit content, manage settings, or perform other operations that normally require a logged‑in user, but the description does not confirm that it grants full administrative control.
Affected Systems
Any WordPress installation that utilizes the weDevs WP User Frontend plugin up to and including version 4.3.11 is affected. This includes sites that have not applied the latest plugin update (4.3.12 or newer).
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium severity range. The EPSS score is not currently available, indicating limited data on exploitation prevalence. Because the flaw is unauthenticated and accessible via publicly exposed web routes, an attacker can trigger it remotely from the internet with no credentials. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed active exploitation at the time of assessment, but the potential to access privileged functionality warrants prompt remediation.
OpenCVE Enrichment