SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-17563

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The User Frontend WordPress plugin prior to version 4.3.11 is vulnerable as it fails to enforce subscription requirements during frontend post submissions, allowing unauthenticated users to create and potentially publish posts meant for paying subscribers. This could lead to unauthorized content being published on sites that rely on subscription models for post submissions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-17563
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.