PT-2026-84683 · WordPress · Wp User Frontend
CVE-2026-81283
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP User Frontend versions prior to 4.3.11
Description
An issue exists that allows for PHP Object Injection, a technique where an attacker leverages the unserialize() function to inject malicious objects into the application logic, potentially leading to remote code execution or unauthorized data access. This specifically affects users with Subscriber privileges.
Recommendations
Update WP User Frontend to version 4.3.11 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp User Frontend