CVE-2026-32485 details a Missing Authorization vulnerability (CWE-862) in the weDevs WP User Frontend plugin, affecting versions up to and including 4.2.8, which allows for the exploitation of incorrectly configured access control security levels. Rated with a CVSS score of 7.5 HIGH, this vulnerability is remotely exploitable with low attack complexity, potentially leading to high confidentiality impact by allowing unauthorized access to sensitive information. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, with its EPSS score indicating a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| WeDevs | WP User Frontend | >= n/a, <= <= 4.2.8CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.