Unauthorized Data Modification in WP Front User Submit Plugin for WordPress
CVE-2025-13419
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 January 2026
What is CVE-2025-13419?
The WP Front User Submit plugin for WordPress is susceptible to unauthorized data modification due to a missing capability check on the '/wp-json/bfe/v1/revert' REST API endpoint. This vulnerability allows unauthenticated attackers to delete arbitrary media attachments, posing a significant risk to users who rely on this functionality. All versions up to and including 5.0.0 are affected, making it crucial for website administrators to implement immediate security measures.
Affected Version(s)
Guest posting / Frontend Posting / Front Editor β WP Front User Submit 0 <= 5.0.0