CVE-2026-95523
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 23, 2026 · Last modified: Sep 23, 2026 · CWE-290
Not enough EPSS history yet.
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-955245.3 MED—
——0Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.5hCVE-2026-944574.8 MED—
——0Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.5hCVE-2026-935115.3 MED10.5%
——3The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events against any order whose transaction id they know.7hCVE-2026-929295.3 MED40.7%
——12OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS web interfaces and disclose configuration information. The underlying design has been present since at least firmware 2.2.3.4.
Upgrade to version 3.5.4.10hCVE-2026-552107.4 HIG31.5%
——9Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by an IdP-asserted email without checking the account's is_external flag. In deployments using mixed local and SAML authentication, an attacker whose IdP session can assert a local user's email can pass POST /api/saml, receive a session for that local account, and access or modify the victim's notes, files, and settings without knowing the local password. This issue is fixed in version 3.7.2.7hCVE-2026-633294.9 MED15.8%
——5Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends the authenticated username. Because the request builder preserves repeated values, a proxied backend that trusts the first x-warpgate-username value can authorize an authenticated attacker as another user. The same forwarding policy also accepts the reserved x-warpgate-authentication-type header, and warpgate-common/src/http_headers.rs does not exclude either reserved identity header. This issue is fixed in version 0.25.6.1d