๐Ÿ” CVE Alert

CVE-2026-14558

UNKNOWN 0.0

WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.

Vendor unknown
Product user frontend
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for unknown user frontend

Be the first to know when new unknown vulnerabilities affecting unknown user frontend are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / User Frontend
0 < 4.3.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/217303f4-4363-46f6-8aee-8e0c1aedc271/

Credits

Hijun Kim WPScan