Impact
The User Frontend WordPress plugin before version 4.3.10 fails to validate field type definitions correctly and deserialises user‑controlled post metadata during post rendering. This flaw allows users with Editor-level access or higher to inject arbitrary PHP objects, which, when combined with a proper PHP Object Propagation (POP) chain present on the site, can execute remote code. The vulnerability directly impacts the confidentiality, integrity, and availability of the affected WordPress installations.
Affected Systems
WordPress sites using the User Frontend plugin with a version older than 4.3.10 are affected. All users assigned Editor or higher roles in such installations are at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability, underscoring the potential for remote code execution, a high‑impact threat. Although the EPSS score is less than 1%, indicating a low probability of exploitation, the risk remains non‑negligible. The vulnerability is not listed in the CISA KEV catalog, yet it is exploitable in any environment where the plugin is active and users with Editor or higher privileges can submit forms. Attackers would need access at the Editor level or above and a suitable PHP Object Propagation chain to exploit the flaw.
OpenCVE Enrichment