User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment Deletion
The WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the Frontend_Form_Ajax::submit_post function. This makes it possible for unauthenticated attackers to delete attachment records through the plugin's AJAX handling when a public frontend form is available.
CVSS—