CVE-2026-42412
MEDIUMCVSS 6.5/10EPSS 0.19%
Last modified
CVE-2026-42412 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-42412?
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WP User Frontend: from n/a through 4.3.1.
How severe is CVE-2026-42412?
CVE-2026-42412 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2026-42412?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-42406A vulnerability exists in BIG-IP and BIG-IQ systems where a …8.7
- CVE-2026-42408When BIG-IP DNS is provisioned, a vulnerability exists in an…6.7
- CVE-2026-42409When an HTTP/2 profile and an iRule containing the HTTP::red…8.7
- CVE-2026-4241A vulnerability was identified in itsourcecode College Manag…6.3
- CVE-2026-42410Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-42411Unauthenticated Broken Authentication in CloudSecure WP Secu…8.1
- CVE-2026-4242A security flaw has been discovered in BabyChakra Pregnancy …2.5
- CVE-2026-42420OpenClaw before 2026.4.8 contains improper input validation …6.5
- CVE-2026-42421OpenClaw before 2026.4.8 contains a session management vulne…5.4
- CVE-2026-42422OpenClaw before 2026.4.8 contains a role bypass vulnerabilit…8.8
- CVE-2026-42423OpenClaw before 2026.4.8 contains an approval-timeout fallba…7.7
- CVE-2026-42424OpenClaw before 2026.4.8 treats shared reply MEDIA paths as …5
Are you affected by CVE-2026-42412?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
