CVE-2026-12406 | wedevs User Frontend Plugin up to 4.3.7 AJAX Action wpuf_file_del post_author access control
A vulnerability described as critical has been identified in wedevs User Frontend Plugin up to 4.3.7. This impacts the function wpuf_file_del of the component AJAX Action Handler. Such manipulation of the argument post_author leads to improper access controls.
This vulnerability is traded as CVE-2026-12406. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More