CVE-2026-12418: CWE-639 Authorization Bypass Through User-Controlled Key in wedevs User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of any arbitrary post on the site, including posts authored by administrators. Exploitation requires access to any WPUF post submission form; this is achievable by users with no WordPress role, as the wpuf_submit_post AJAX action is gated only by a nonce with no capability check for the downstream post-edit operation.
AI Analysis
Technical Summary
CVE-2026-12418 is an authorization bypass vulnerability (CWE-639) in the User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration WordPress plugin by wedevs. The vulnerability exists in all versions up to and including 4.3.7 and is caused by missing validation on the 'wpuf_files_data' parameter, allowing unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of arbitrary posts. The wpuf_submit_post AJAX action is gated solely by a nonce without verifying user capabilities, enabling attackers without any WordPress role to exploit this via any WPUF post submission form.
Potential Impact
An unauthenticated attacker can modify the content of any post on the affected WordPress site, including posts authored by administrators. This can lead to content tampering, misinformation, or defacement. The vulnerability does not affect confidentiality or availability but impacts the integrity of site content.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to WPUF post submission forms and monitor for suspicious activity related to the 'wpuf_submit_post' AJAX action. Consider disabling or limiting the plugin functionality if possible to reduce exposure.
CVE-2026-12418: CWE-639 Authorization Bypass Through User-Controlled Key in wedevs User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration
Description
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of any arbitrary post on the site, including posts authored by administrators. Exploitation requires access to any WPUF post submission form; this is achievable by users with no WordPress role, as the wpuf_submit_post AJAX action is gated only by a nonce with no capability check for the downstream post-edit operation.
CVSS v3.1
Score 5.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-12418 is an authorization bypass vulnerability (CWE-639) in the User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration WordPress plugin by wedevs. The vulnerability exists in all versions up to and including 4.3.7 and is caused by missing validation on the 'wpuf_files_data' parameter, allowing unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of arbitrary posts. The wpuf_submit_post AJAX action is gated solely by a nonce without verifying user capabilities, enabling attackers without any WordPress role to exploit this via any WPUF post submission form.
Potential Impact
An unauthenticated attacker can modify the content of any post on the affected WordPress site, including posts authored by administrators. This can lead to content tampering, misinformation, or defacement. The vulnerability does not affect confidentiality or availability but impacts the integrity of site content.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to WPUF post submission forms and monitor for suspicious activity related to the 'wpuf_submit_post' AJAX action. Consider disabling or limiting the plugin functionality if possible to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-06-16T16:03:46.619Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4f598768715ace43f21913
Added to database: 07/09/2026, 08:19:19 UTC
Last enriched: 07/16/2026, 10:02:29 UTC
Last updated: 08/22/2026, 18:37:28 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.