CVE-2026-2233 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modif…
Medium CVSS: 5.3

CVE-2026-2233

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to modify arbitrary posts (e.g. unpublish published posts and overwrite the contents) via the 'post_id' parameter.
Vendor
-
Product
-
CWE
CWE-862
Yayın Tarihi
2026-03-16 14:19:28
Güncelleme
2026-03-16 14:53:07
Source Identifier
security@wordfence.com
KEV Date Added
-

Kategoriler

Referanslar