PatchSiren

User Frontend CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH User Frontend CVE published 2026-09-02

CVE-2026-19116

The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site.

MEDIUM User Frontend CVE published 2026-07-27

CVE-2026-14568

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment. This allows unauthenticated attackers to permanently delete author-less attachments, such as guest uploads and placeholder media. Users should verify plugin version and update to 4.3.8 or later [truncated]