{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T08:22:48.259","vulnerabilities":[{"cve":{"id":"CVE-2026-2233","sourceIdentifier":"security@wordfence.com","published":"2026-03-16T14:19:28.950","lastModified":"2026-06-17T10:30:35.970","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to modify arbitrary posts (e.g. unpublish published posts and overwrite the contents) via the 'post_id' parameter."},{"lang":"es","value":"El plugin User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership &amp; User Registration para WordPress es vulnerable a la modificación no autorizada de datos debido a una comprobación de capacidad faltante en la función draft_post() en todas las versiones hasta la 4.2.8, inclusive. Esto hace posible que atacantes no autenticados modifiquen publicaciones arbitrarias (por ejemplo, despublicar publicaciones ya publicadas y sobrescribir el contenido) a través del parámetro 'post_id'."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wedevs","product":"User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.2.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-16T19:11:22.434917Z","id":"CVE-2026-2233","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset/3468395/wp-user-frontend","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e0a278a3-f229-4673-8b3e-5b68f383dcc7?source=cve","source":"security@wordfence.com"}]}}]}