CVE-2026-14558
WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
| Vendor | unknown |
| Product | user frontend |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown user frontend
Be the first to know when new unknown vulnerabilities affecting unknown user frontend are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / User Frontend
0 < 4.3.10
References
Credits
Hijun Kim WPScan