CVE-2026-81283
largeSubscriber-level PHP Object Injection in WP User Frontend WordPress Plugin
A PHP object injection vulnerability (CWE-502, unsafe deserialization of untrusted data) affects the WP User Frontend plugin in versions 4.3.10 and earlier. An attacker holding, or able to register for, a subscriber-level account on the site can send crafted serialized data to the vulnerable code path over the network, with no user interaction required. Successful exploitation allows injection of arbitrary PHP objects and, depending on the classes and gadget chains available on the site, can lead to information disclosure, file manipulation, or potentially code execution, reflected in the 8.8 (high) CVSS score with high impact to confidentiality, integrity, and availability. Any WordPress site running WP User Frontend 4.3.10 or older is affected, which plausibly covers tens of thousands of sites. No public proof-of-concept or in-the-wild exploitation is currently known; EPSS estimates only about a 0.5% probability of exploitation within 30 days, and the issue is not in CISA KEV.
What to do: Update WP User Frontend to the latest available release (anything newer than 4.3.10, per the vendor's changelog) as soon as possible. In the interim, disable or restrict open subscriber registration and review recent activity by subscriber-level accounts for signs of crafted serialized payloads. Because exploitation requires an authenticated subscriber, prioritize patching sites where the plugin is active and self-registration is enabled.
| weDevs WP User Frontend (WordPress plugin) | <= 4.3.10 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.