Impact
The vulnerability allows an attacker to delete arbitrary files within the WordPress installation that uses the WP User Frontend plugin version 4.3.11 or earlier. Deleting critical files can lead to site defacement, loss of content, and disruption of services, thereby impacting the integrity and availability of the site.
Affected Systems
The plugin is produced by weDevs, known as WP User Frontend, and any WordPress site running this plugin at version 4.3.11 or earlier is affected. The issue is specifically tied to subscribers, who can trigger the deletion function.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request that triggers the deletion functionality; successful exploitation would likely require a user with subscriber privileges and access to the vulnerability‑exploiting endpoint.
OpenCVE Enrichment