Arbitrary File Upload Vulnerability in User Frontend Plugin for WordPress
CVE-2026-1565
8.8HIGH
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 26 February 2026
What is CVE-2026-1565?
The User Frontend plugin for WordPress is susceptible to arbitrary file uploads due to insufficient validation of file types in critical functions. Authenticated users with at least Author-level permissions can exploit this flaw, enabling them to upload potentially malicious files to the server. This flaw presents a significant security risk, as it could lead to remote code execution threats, compromising the integrity and security of the website.
Affected Version(s)
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration 0 <= 4.2.8