Impact
The vulnerability is a PHP Object Injection flaw in the WordPress WP User Frontend plugin. Based on the description, it is inferred that an attacker could supply specially crafted serialized data that is processed by the plugin, leading to arbitrary object deserialization and execution of code due to improper validation. This capability would allow modification of server behavior and execution of malicious code, potentially compromising confidentiality, integrity, and availability. The weakness is identified as CWE-502.
Affected Systems
Affected systems are installations of the weDevs WP User Frontend plugin version 4.3.10 or earlier. The problem exists specifically in plugin releases up to and including 4.3.10; any deployment that has not upgraded to 4.3.11 or later is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack could be carried out over the web by submitting specially crafted requests to the front‑end submission mechanism, resulting in remote code execution. The likely attack vector is the plugin’s front‑end submission endpoint. Given the high severity and the widespread exposure of WordPress sites, the risk remains significant.
OpenCVE Enrichment