Arbitrary File Upload Vulnerability in User Frontend Plugin for WordPress
CVE-2026-1565
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 26 February 2026
What is CVE-2026-1565?
The User Frontend plugin for WordPress is susceptible to arbitrary file uploads due to insufficient validation of file types in critical functions. Authenticated users with at least Author-level permissions can exploit this flaw, enabling them to upload potentially malicious files to the server. This flaw presents a significant security risk, as it could lead to remote code execution threats, compromising the integrity and security of the website.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration * <= 4.2.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved