Impact
The User Frontend WordPress plugin before version 4.3.10 fails to validate field type definitions correctly and deserialises user-controlled post metadata during post rendering. This flaw allows users with Editor-level access or higher to inject arbitrary PHP objects, which, when combined with a proper PHP Object Propagation (POP) chain present on the site, can execute remote code. The vulnerability directly impacts the confidentiality, integrity, and availability of the affected WordPress installations.
Affected Systems
WordPress sites using the User Frontend plugin with a version older than 4.3.10 are affected. All users assigned Editor or higher roles in such installations are at risk.
Risk and Exploitability
Although an EPSS score is not available, the lack of a CVSS score suggests the severity is significant, and the high impact of remote code execution indicates a serious threat. The vulnerability is not listed in CISA KEV, but it remains exploitable in any environment where the plugin is active and higher privilege users can submit forms. Attackers would need Editor or higher level access and a suitable POP chain to exploit the flaw.
OpenCVE Enrichment