Description
Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dynamic User Directory (<= 2.4) contains a PHP Object Injection flaw that is triggered via subscriber input. When special crafted serialized data is processed, an attacker can instantiate arbitrary PHP objects and execute code with the privileges of the web server. The vulnerability is a classic remote code execution vector originating from PHP deserialization mistakes.

Affected Systems

WordPress sites that have installed Dynamic User Directory plugin by Sarah Giles, on any version 2.4 or earlier. No other vendors or products were identified as affected.

Risk and Exploitability

The CVSS score of 9.8 shows this is a critical flaw. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the severity alone indicates a high risk. The likely attack vector is a remote HTTP request that submits crafted serialized input to the plugin; security controls that allow unauthenticated or low‑privilege posting can be abused. Given high severity, this flaw should be treated as a major threat if the plugin is in use.

Generated by OpenCVE AI on October 10, 2026 at 20:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Dynamic User Directory to a version newer than 2.4 that removes the deserialization logic
  • If an update is not immediately possible, remove or deactivate the plugin to prevent the vulnerable code from executing
  • Apply a security measure that blocks processing of serialized data from untrusted sources, such as whitelisting input or filtering payloads that contain PHP serialization markers

Generated by OpenCVE AI on October 10, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
Title WordPress Dynamic User Directory plugin <= 2.4 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:18.996Z

Reserved: 2026-04-29T09:05:20.866Z

Link: CVE-2026-42719

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:37.030

Modified: 2026-10-10T20:16:37.030

Link: CVE-2026-42719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T21:00:10Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data