CVE-2026-17563
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Sep 02, 2026
Vendor
unknown
Description
The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.