ZeroHour

CVE-2026-81283

large

Subscriber-level PHP Object Injection in WP User Frontend WordPress Plugin

CVSS 3.1
8.8 high
EPSS
<1%p40
Published
()
Modified
AI analysis

A PHP object injection vulnerability (CWE-502, unsafe deserialization of untrusted data) affects the WP User Frontend plugin in versions 4.3.10 and earlier. An attacker holding, or able to register for, a subscriber-level account on the site can send crafted serialized data to the vulnerable code path over the network, with no user interaction required. Successful exploitation allows injection of arbitrary PHP objects and, depending on the classes and gadget chains available on the site, can lead to information disclosure, file manipulation, or potentially code execution, reflected in the 8.8 (high) CVSS score with high impact to confidentiality, integrity, and availability. Any WordPress site running WP User Frontend 4.3.10 or older is affected, which plausibly covers tens of thousands of sites. No public proof-of-concept or in-the-wild exploitation is currently known; EPSS estimates only about a 0.5% probability of exploitation within 30 days, and the issue is not in CISA KEV.

What to do: Update WP User Frontend to the latest available release (anything newer than 4.3.10, per the vendor's changelog) as soon as possible. In the interim, disable or restrict open subscriber registration and review recent activity by subscriber-level accounts for signs of crafted serialized payloads. Because exploitation requires an authenticated subscriber, prioritize patching sites where the plugin is active and self-registration is enabled.

Affected
weDevs WP User Frontend (WordPress plugin)<= 4.3.10
Estimated exposure
largetens of thousands of WordPress sites (~30,000-40,000 active installs of the plugin) — WP User Frontend is distributed on WordPress.org with roughly 30,000-40,000 active installations, and every site running version 4.3.10 or older is vulnerable if the plugin is active; the number of sites with subscriber registration…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.

Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.