Unauthorized Data Modification in WordPress User Frontend Plugin
CVE-2026-4058
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 9 June 2026
What is CVE-2026-4058?
The User Frontend plugin for WordPress enables users to post content, manage profiles, and handle memberships. However, versions up to and including 4.3.2 face a significant flaw that allows authenticated users with a Subscriber role or higher to cancel any user's subscription. This vulnerability stems from a missing capability check in the user_subscription_cancel() function, raising serious concerns about user data integrity and access control.
Affected Version(s)
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration 0 <= 4.3.2