CVE-2026-12418 Details
Description
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of any arbitrary post on the site, including posts authored by administrators. Exploitation requires access to any WPUF post submission form; this is achievable by users with no WordPress role, as the wpuf_submit_post AJAX action is gated only by a nonce with no capability check for the downstream post-edit operation.
A vulnerability exists in the User Frontend WordPress plugin, specifically in the AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration features, in all versions through 4.3.7. The issue is an Insecure Direct Object Reference (IDOR) that allows unauthenticated users to manipulate the 'wpuf_files_data' parameter without proper validation. This exploitation enables attackers to overwrite the post title, content, and excerpt of any post on the site, including those written by administrators. The vulnerability can be exploited by accessing any WPUF post submission form, which is available to users without a WordPress role, as the wpuf_submit_post AJAX action only requires a nonce and lacks a capability check for the post-editing process.
Users are advised to update the User Frontend WordPress plugin to version 4.3.8 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| User Frontend | <= 4.3.7 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion