Subscriber Bypass Vulnerability in WP User Frontend by WordPress
CVE-2026-95523

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 September 2026

What is CVE-2026-95523?

A bypass vulnerability in WP User Frontend versions up to 4.3.11 allows unauthorized users to gain access to restricted subscriber functions. This flaw can lead to unauthorized viewing or modification of users’ data, posing serious risks to site integrity and user privacy. It is vital for users of older versions to update immediately to safeguard against potential exploits.

Affected Version(s)

WP User Frontend <= 4.3.11

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.