Vulnerability in User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission — CVE-2026-96574
What to do now
Update User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission to 4.3.13 or later.
Affected versions
- Everything up to and including 4.3.12
Affected: User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission (plugin, wp-user-frontend)
What the vulnerability is
The User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpuf_payment_method' parameter in all versions up to, and including, 4.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass technique involves appending a valid gateway keyword such as 'bank' to the HTML payload, causing sanitize_text_field() to yield only the keyword for routing purposes while the full malicious raw value is stored and later rendered unescaped.