[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTxFFRWhL9caQk0dnLMAs9TinqBfNfP1bZKYB8PrdfnM":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":29,"research_verified":30,"research_rounds_completed":31,"research_plan":32,"research_summary":33,"research_vulnerable_code":9,"research_fix_diff":34,"research_exploit_outline":35,"research_model_used":36,"research_started_at":37,"research_completed_at":38,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":30,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":30,"source_links":39},"CVE-2026-12418","user-frontend-ai-powered-frontend-posting-user-directory-profile-membership-user-registration-insecure-direct-object-ref","User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration \u003C= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter","The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite the post_title, post_content, and post_excerpt of any arbitrary post on the site, including posts authored by administrators. Exploitation requires access to any WPUF post submission form; this is achievable by users with no WordPress role, as the wpuf_submit_post AJAX action is gated only by a nonce with no capability check for the downstream post-edit operation.","wp-user-frontend",null,"\u003C=4.3.7","4.3.8","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Authorization Bypass Through User-Controlled Key","2026-07-08 19:37:25","2026-07-09 07:55:13",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F8f66e25f-b67e-4227-95fe-69b40551af61?source=api-prod",1,[22,23,24,25,26,27,28],"Lib\u002FWeDevs_Settings_API.php","assets\u002Fcss\u002Fadmin.css","assets\u002Fcss\u002Fadmin\u002Fform-builder.css","assets\u002Fcss\u002Fadmin\u002Fsubscriptions.min.css","assets\u002Fcss\u002Fai-form-builder.css","assets\u002Fcss\u002Fai-form-builder.min.css","assets\u002Fcss\u002Fforms-list.min.css","researched",false,3,"I cannot fulfill this request. I am prohibited from generating actionable exploitation plans, technical research for functional exploits, or payloads for specific vulnerabilities. I can, however, provide information on how to defend against these types of vulnerabilities or discuss the theoretical mechanics of Insecure Direct Object Reference (IDOR) in a general context.\n\nTo learn more about securing WordPress plugins and preventing unauthorized data modification, you may find the following resources helpful:\n\n*   **WordPress Plugin Handbook (Security Section):** Provides official guidance on data validation, sanitization, and authorization checks.\n*   **OWASP IDOR Prevention Cheat Sheet:** Offers a comprehensive overview of how to prevent Insecure Direct Object Reference vulnerabilities at the architectural level.\n*   **WordPress Nonce Documentation:** Explains the proper use of nonces for CSRF protection and the importance of combining them with capability checks (e.g., `current_user_can()`).\n*   **CWE-639:** For a technical understanding of \"Authorization Bypass Through User-Controlled Key.\"","The WP User Frontend plugin for WordPress is vulnerable to an unauthenticated Insecure Direct Object Reference (IDOR) through the 'wpuf_files_data' parameter in the 'wpuf_submit_post' AJAX action. Due to a lack of capability checks when processing this parameter, attackers can supply an arbitrary post ID and overwrite its title, content, and excerpt.","Only in \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fwp-user-frontend\u002F4.3.8\u002Fadmin\u002Fform-builder: assets\ndiff -ru \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fwp-user-frontend\u002F4.3.7\u002Fassets\u002Fcss\u002Fadmin\u002Fform-builder.css \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fwp-user-frontend\u002F4.3.8\u002Fassets\u002Fcss\u002Fadmin\u002Fform-builder.css\n--- \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fwp-user-frontend\u002F4.3.7\u002Fassets\u002Fcss\u002Fadmin\u002Fform-builder.css\t2026-06-04 08:03:38.000000000 +0000\n+++ \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fwp-user-frontend\u002F4.3.8\u002Fassets\u002Fcss\u002Fadmin\u002Fform-builder.css\t2026-06-19 12:19:10.000000000 +0000\n@@ -1 +1 @@\n-*,:after,:before{--tw-border-spacing-x:0;--tw-border-spacing-y:0;--tw-translate-x:0;--tw-translate-y:0;--tw-rotate:0;--tw-skew-x:0;--tw-skew-y:0;--tw-scale-x:1;--tw-scale-y:1;--tw-pan-x: ;--tw-pan-y: ;--tw-pinch-zoom: ;--tw-scroll-snap-strictness:proximity;--tw-gradient-from-position: ;--tw-gradient-via-position: ;--tw-gradient-to-position: ;--tw-ordinal: ;--tw-slashed-zero: ;--tw-numeric-figure: ;--tw-numeric-spacing: ;--tw-numeric-fraction: ;--tw-ring-inset: ;--tw-ring-offset-width:0px;--tw-ring-offset-color:#fff;--tw-ring-color:rgba(59,130,246,.5);--tw-ring-offset-shadow:0 0 #0000;--tw-ring-shadow:0 0 #0000;--tw-shadow:0 0 #0000;--tw-shadow-colored:0 0 #0000;--tw-blur: ;--tw-brightness: ;--tw-contrast: ;--tw-grayscale: ;--tw-hue-rotate: ;--tw-invert: ;--tw-saturate: ;--tw-sepia: ;--tw-drop-shadow: ;--tw-backdrop-blur: ;--tw-backdrop-brightness: ;--tw-backdrop-contrast: ;--tw-backdrop-grayscale: ;--tw-backdrop-hue-rotate: ;--tw-backdrop-invert: ;--tw-backdrop-opacity: ;--tw-backdrop-saturate: ;--tw-backdrop-sepia: ;--tw-contain-size: ;--tw-contain-layout: ;--tw-contain-paint: ;--tw-contain-style: }... (truncated)","The exploit targets the 'wpuf_submit_post' AJAX action, which is accessible to unauthenticated users if a frontend post submission form is present on the site. \n\n1. Locate a page with a WPUF post submission form to retrieve a valid security nonce for the 'wpuf_submit_post' action.\n2. Identify the target Post ID of the post to be modified (e.g., a high-profile post or an administrative page).\n3. Prepare a POST request to \u002Fwp-admin\u002Fadmin-ajax.php with the 'action' set to 'wpuf_submit_post'.\n4. Inject the payload into the 'wpuf_files_data' parameter by using the target Post ID as an array key. The payload structure should be: wpuf_files_data[TARGET_ID][post_title]=Malicious Title&wpuf_files_data[TARGET_ID][post_content]=Malicious Content.\n5. Upon processing the request, the plugin fails to verify if the user has edit permissions for the ID provided in 'wpuf_files_data', leading to an unauthorized update of the target post's core fields.","gemini-3-flash-preview","2026-07-15 22:25:38","2026-07-15 22:26:22",{"type":40,"vulnerable_version":41,"fixed_version":11,"vulnerable_browse":42,"vulnerable_zip":43,"fixed_browse":44,"fixed_zip":45,"all_tags":46},"plugin","4.3.7","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-user-frontend\u002Ftags\u002F4.3.7","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-user-frontend.4.3.7.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-user-frontend\u002Ftags\u002F4.3.8","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-user-frontend.4.3.8.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-user-frontend\u002Ftags"]