Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress-extensions
Wordpress-extensions wp User Frontend |
|
| Vendors & Products |
Wordpress-extensions
Wordpress-extensions wp User Frontend |
Fri, 02 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 02 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
ssvc
|
Fri, 02 Oct 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 02 Oct 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers. | |
| Title | WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-02T10:54:10.793Z
Reserved: 2026-08-25T08:06:20.113Z
Link: CVE-2026-79618
Updated: 2026-10-02T10:44:42.752Z
Status : Deferred
Published: 2026-10-02T07:16:37.873
Modified: 2026-10-02T18:00:34.733
Link: CVE-2026-79618
No data.
OpenCVE Enrichment
Updated: 2026-10-04T20:56:10Z
-
CWE-862
Missing Authorization