Impact
The User Frontend WordPress plugin fails to validate deserialization of user-supplied fields when an existing post is reopened in its frontend edit form. An authenticated subscriber or higher can submit crafted serialized data, triggering PHP Object Injection. This flaw is a form of deserialization of untrusted data (CWE‑502) that can lead to remote code execution if the site contains a suitable gadget chain. The vulnerability allows attackers to run arbitrary code on the server, compromising confidentiality, integrity, and availability.
Affected Systems
All WordPress sites that install the User Frontend plugin with a version older than 4.3.11 are affected. The issue applies to subscribers and roles above, as they can access the frontend post edit form. No other vendors or products are listed as impacted.
Risk and Exploitability
Although the CVSS score is not provided and EPSS is unavailable, the exploit requires an authenticated user and a gadget chain on the target. The vulnerability is listed as not in CISA KEV. If a suitable gadget chain exists, the risk is high; otherwise the potential impact remains moderate. The likely attack vector is through the web interface, limited to accounts with subscriber‑level access or higher.
OpenCVE Enrichment