What is CVE-2026-14568?
The User Frontend WordPress plugin before version 4.3.8 fails to verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments. Users should immediately update to version 4.3.8 or later to mitigate this vulnerability.
Azərbaycanca: CVE-2026-14568 istifadəçi frontend plaginində (4.3.8-dən əvvəlki versiyalarda) aşkarlanan zəiflikdir. Bu, autentifikasiya olunmamış hücumçulara müəllifi olmayan əlavə faylları (attachments) qalıcı silməyə imkan verir, çünki plagin silmədən əvvəl fayl sahibliyini düzgün yoxlamır. İstifadəçilər plaginini dərhal 4.3.8 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the User Frontend plugin are affected by CVE-2026-14568?
Versions prior to 4.3.8 are affected by this vulnerability.
What must users do to mitigate CVE-2026-14568?
Users should immediately update the plugin to version 4.3.8 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.