Description
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4.2.8. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
* (semver)
Timeline
| 2026-01-28: | Vendor Notified |
| 2026-02-26: | Disclosed |
Credits
Williwollo
References
www.wordfence.com/...-7600-43a1-94a3-1530cdb5a9f3?source=cve
plugins.trac.wordpress.org/...admin-settings.php?rev=3448772
plugins.trac.wordpress.org/...admin-settings.php?rev=3448772
plugins.trac.wordpress.org/...in/Admin_Tools.php?rev=3448772
plugins.trac.wordpress.org/...in/Admin_Tools.php?rev=3448772
plugins.trac.wordpress.org/...includes/Admin/Admin_Tools.php