CVE-2026-42412 - WordPress WP User Frontend plugin <= 4.3.1 - Broken Access Control vulnerability
CVE ID :CVE-2026-42412 Published : April 29, 2026, 7:51 a.m. | 1 hour, 34 minutes ago Description :Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.
ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Critical Flaw Turns Vect Ransomware into Data Destroying Wiper
- [CYBER] CISA orders feds to patch Windows flaw exploited as zero-day
- [CYBER] CVE-2026-42167 Allows Auth Bypass And RCE In ProFTPD
- [CYBER] CISA, Microsoft warn of active exploitation of Windows Shell vulnerability (CVE-2026-32202)
- [CYBER] Ransomware accidentally destroys all files larger than 128KB, preventing decryption — VECT code likely partly vibe coded with AI or used an old code base, security researchers suggest
- [CYBER] RIPE NCC RPKI exploit chain