PT-2026-84683 · WordPress · Wp User Frontend

CVE-2026-81283

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP User Frontend versions prior to 4.3.11
Description An issue exists that allows for PHP Object Injection, a technique where an attacker leverages the unserialize() function to inject malicious objects into the application logic, potentially leading to remote code execution or unauthorized data access. This specifically affects users with Subscriber privileges.
Recommendations Update WP User Frontend to version 4.3.11 or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81283

Affected Products

Wp User Frontend