PT-2026-38892 · WordPress · Wp User Frontend

D.V4N_S3C

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-5127

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration versions prior to 4.3.2
Description Insufficient input validation and type checking on the wpuf files parameter during form submission, combined with unconditional deserialization via the maybe unserialize() function when displaying post content, allows authenticated attackers with Subscriber-level access or higher to inject arbitrary PHP objects. This can lead to arbitrary code execution, deletion of arbitrary files, or other malicious actions if a POP (Property-Oriented Programming) chain—a sequence of gadgets used to execute code during deserialization—is present on the target system.
Recommendations Update to a version newer than 4.3.1. As a temporary workaround, restrict access to the wpuf files parameter during form submissions to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-5127

Affected Products

Wp User Frontend