Eklenti güvenlik geçmişi
User Frontend güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission eklentisi için 24 açık kaydı bulunuyor; en yenisi 30 Eylül 2026 tarihli. Bunların 7 tanesi kritik veya yüksek önemde, 13 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 4.3.13.
- Toplam kayıt
- 24
- Kritik veya yüksek
- 7
- Oturumsuz istismar
- 13
- Son kayıt
- 30 Eylül 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
eksik yetki denetimi
Etkilenen sürümler: 4.3.12 öncesi · Oturum açmadan istismar edilebilir
4.3.12 sürümünden önceki User Frontend WordPress eklentisi, hesap oluşturulmadan önce sitenin kullanıcı kaydına izin verip vermediğini kontrol etmez; bu da, kaydın devre dışı bırakıldığı sitelerde kimliği doğrulanmamış kullanıcıların hesap açmasına olanak tanır. Oluşturulan hesap, sitenin varsayılan rolünü alır.
yetki yükseltme
Etkilenen sürümler: 4.3.12 öncesi · Oturum açmadan istismar edilebilir
4.3.12 sürümünden önceki User Frontend WordPress eklentisi, kayıt formu aracılığıyla atanan rolün tahrif edilmesini engellemez; bu da kimliği doğrulanmamış kullanıcıların Editör gibi daha yüksek ayrıcalıklı bir rolle kayıt olmalarına olanak tanır. Bu sorun, sodium uzantısının bulunmadığı ve bir kayıt sayfasının yapılandırılmış olduğu PHP sürümlerini çalıştıran kurulumları etkiler. Yönetici rolü bu yolla elde edilemez.
Türkçe kayıt ve ne yapmalırastgele dosya silme
Etkilenen sürümler: 4.3.11 ve öncesi
WP User Frontend'in 4.3.11 ve önceki sürümlerinde abone tarafından keyfi dosya silme sorunu.
güvenlik
Etkilenen sürümler: 4.3.11 ve öncesi · Oturum açmadan istismar edilebilir
WP User Frontend'ın 4.3.11 ve önceki sürümlerinde kimlik doğrulaması gerektirmeyen bir atlama güvenlik açığı.
güvenlik
Etkilenen sürümler: 4.3.11 ve öncesi
WP User Frontend'ın 4.3.11 ve önceki sürümlerinde bulunan abone atlama güvenlik açığı.
eksik yetki denetimi
Etkilenen sürümler: 4.3.11 öncesi · Oturum açmadan istismar edilebilir
4.3.11 sürümünden önceki User Frontend WordPress eklentisi, ön uçtan gönderilen yazıların işlenmesi sırasında abonelik satın alma şartını uygulamamakta, yalnızca formun görüntülenmesi sırasında bu şartı uygulamaktadır. Bu durum, kimliği doğrulanmamış kullanıcıların, ücretli abonelere sınırlı formlar aracılığıyla yazı oluşturmasına ve formun yapılandırmasına bağlı olarak bu yazıları anında yayınlamasına olanak tanımaktadır.
PHP nesne enjeksiyonu
Etkilenen sürümler: 4.3.10 ve öncesi
WP User Frontend'ın 4.3.10 ve önceki sürümlerinde Abone PHP Nesnesi Enjeksiyonu.
PHP nesne enjeksiyonu
Etkilenen sürümler: 4.3.11 öncesi
User Frontend WordPress eklentisinin 4.3.11 sürümünden önceki eklentisi, gönderilen bir yazının ön uç düzenleme formunda yeniden açılması durumunda kullanıcı tarafından girilen alan değerlerinin serileştirilmesini engellemez; bu da, abone düzeyinde veya daha yüksek erişim iznine sahip kimliği doğrulanmış kullanıcıların PHP Nesne Enjeksiyonu gerçekleştirmesine olanak tanır. Bu durum, sitede uygun bir gadget zinciri mevcut olduğunda uzaktan kod yürütülmesine yol açabilir.
hassas bilgi ifşası
Etkilenen sürümler: 4.3.10 öncesi · Oturum açmadan istismar edilebilir
4.3.10 sürümünden önceki User Frontend WordPress eklentisi, kullanıcı dizini arama uç noktasına erişimi kısıtlamadığından, kimlik doğrulaması yapılmamış saldırganların, yöneticiler dahil olmak üzere tüm kayıtlı kullanıcıların e-posta adreslerini ve telefon numaralarını elde etmesine olanak tanır.
PHP nesne enjeksiyonu
Etkilenen sürümler: 4.3.10 öncesi
4.3.10 sürümünden önceki User Frontend WordPress eklentisi, alan türü tanımlarını düzgün bir şekilde doğrulamamakta ve gönderilen gönderileri işlerken kullanıcı tarafından kontrol edilen gönderi meta verilerini serileştirmeyi kaldırmaktadır. Bu durum, Editör düzeyinde ve üzeri erişim hakkına sahip kullanıcıların keyfi PHP nesneleri eklemesine olanak tanır; bu da sitede uygun bir POP zinciri mevcut olduğunda uzaktan kod yürütülmesine yol açabilir.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 4.3.7 ve öncesi · Oturum açmadan istismar edilebilir
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of any arbitrary post on the site, including posts authored by administrators. Exploitation requires access to any WPUF post submission form; this is achievable by users with no WordPress role, as the wpuf_submit_post AJAX action is gated only by a nonce with no capability check for the downstream post-edit operation.
eksik yetki denetimi
Etkilenen sürümler: 4.3.7 ve öncesi · Oturum açmadan istismar edilebilir
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to delete arbitrary media attachments whose post_author is 0, such as guest and registration-form uploads, via the wpuf_file_del AJAX action. This is exploitable by unauthenticated visitors on any site where a WPUF shortcode is rendered on a front-end page, as this causes the valid wpuf_nonce value to be localized into publicly accessible JavaScript objects (wpuf_upload and wpuf_frontend), satisfying the sole access control gate.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 4.3.1 ve öncesi · Oturum açmadan istismar edilebilir
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to activate a free subscription pack for any user on the site, overwriting their existing paid subscription and causing loss of paid features.
eksik yetki denetimi
Etkilenen sürümler: 4.3.7 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
PHP nesne enjeksiyonu
Etkilenen sürümler: 4.3.1 ve öncesi
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form submission, combined with unconditional deserialization via maybe_unserialize() when displaying post content. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP objects, which can be leveraged to execute arbitrary code, delete arbitrary files, or perform other malicious actions if a POP chain is present on the target system.
eksik yetki denetimi
Etkilenen sürümler: 4.3.1 ve öncesi · Oturum açmadan istismar edilebilir
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.
eksik yetki denetimi
Etkilenen sürümler: 4.2.8 ve öncesi · Oturum açmadan istismar edilebilir
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.
eksik yetki denetimi
Etkilenen sürümler: 4.2.5 ve öncesi
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5.
eksik yetki denetimi
Etkilenen sürümler: 4.2.8 ve öncesi · Oturum açmadan istismar edilebilir
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to modify arbitrary posts (e.g. unpublish published posts and overwrite the contents) via the 'post_id' parameter.
kısıtlamasız dosya yükleme
Etkilenen sürümler: 4.2.8 ve öncesi
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4.2.8. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
eksik yetki denetimi
Etkilenen sürümler: 4.2.4 ve öncesi · Oturum açmadan istismar edilebilir
The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including, 4.2.4. This makes it possible for unauthenticated attackers to delete attachment.
uzaktan kod çalıştırma
Etkilenen sürümler: 4.1.12 ve öncesi
Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12.
eksik yetki denetimi
Etkilenen sürümler: 4.1.12 ve öncesi
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12.
eksik yetki denetimi
Etkilenen sürümler: 3.6.8 ve öncesi
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Türkçe açıklamalar makine çevirisidir; bağlayıcı metin NVD’deki İngilizce kayıttır. Veri 7 Ekim 2026 itibarıyla.