Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers. | |
| Title | WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T14:57:38.402Z
Reserved: 2026-07-27T14:28:04.730Z
Link: CVE-2026-17563
Updated: 2026-09-02T14:44:27.904Z
Status : Received
Published: 2026-09-02T15:17:37.717
Modified: 2026-09-02T15:17:37.717
Link: CVE-2026-17563
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization