Unauthorized Data Modification in WordPress User Frontend Plugin by WP Everest
CVE-2026-2233
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 15 March 2026
What is CVE-2026-2233?
The User Frontend plugin for WordPress, developed by WP Everest, is susceptible to unauthorized data modifications due to a lack of necessary capability checks in the draft_post() function. This vulnerability affects all versions up to and including 4.2.8, allowing unauthenticated attackers to manipulate published posts by changing or deleting their contents through the 'post_id' parameter. As such, this exploit poses serious risks to website content integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration * <= 4.2.8