CVE-2026-1565Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4.2.8. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-26); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-26: 3Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-26: 3Technical Details · 2026-02-27: 2Technical Details · 2026-03-03: 102-2602-2703-03
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-263
Disclosure2Patch1
2026-02-272
Disclosure2
2026-03-031
General1
Full discourse6 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1565 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due… https://www.cve.org/CVERecord?id=CVE-2026-1565 ----- Traducción: CVE-2026-1565 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-1565, noting that the User Frontend WordPress plugin is vulnerable to arbitrary file uploads, with no PoC, exploit, or patch mentioned.

    0001070
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1565 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due… https://www.cve.org/CVERecord?id=CVE-2026-1565

    Post summary

    The WordPress plugin "User Frontend" is disclosed to have an arbitrary file upload vulnerability (CVE‑2026‑1565), but no PoC, exploit code, or patch details are provided.

    000101.1K
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-1565 pertains to a critical security flaw in the **User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration** plugin for WordPress, specifically affecting all versions up to and including 4.2.8. The core issue lies in improper validation of uploaded files, allowing authenticated users with at least Author-level privileges to upload arbitrary files to the server. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-1565

    Post summary

    The post announces a critical WordPress plugin flaw (CVE-2026-1565) that permits authenticated users to upload arbitrary files due to improper validation, but it does not provide a PoC, exploit, or patch information.

    0001041
    20 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-1565 (CVSS:8.8, HIGH) is Awaiting Analysis. The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP..https://nvd.nist.gov/vuln/detail/CVE-2026-1565 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-1565 with a high CVSS score and plugin context but provides no further details on exploitation, patches, or PoC.

    0000035
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1565 - High The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type ... https://www.thehackerwire.com/vulnerability/CVE-2026-1565/ https://t.co/0ngvvLDgUI

    Post summary

    The post announces a high‑severity CVE‑2026‑1565 affecting a WordPress plugin, highlighting an arbitrary file upload flaw caused by incorrect file type validation, but it does not provide a PoC, exploit, or patch details.

    0000056
    119 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1565: HIGH] Cybersecurity alert: Vulnerabilities found in User Frontend WordPress plugin can allow attackers to upload arbitrary files for potential remote code execution. Update to version 4.2.9 ASAP.#cve,CVE-2026-1565,#cybersecurity https://cvefind.com/CVE-2026-1565

    Post summary

    The post alerts about CVE‑2026‑1565 in the User Frontend WordPress plugin, noting that it permits arbitrary file uploads that could enable remote code execution, and urges users to update to version 4.2.9 immediately.

    0000045
    585 followersView on X

Explore more