CyberRota Analysis
AI-GeneratedThe User Frontend WordPress plugin prior to version 4.3.10 is vulnerable due to improper validation of field type definitions and deserialization of user-controlled post metadata. This flaw allows users with Editor-level access and higher to inject arbitrary PHP objects, potentially leading to remote code execution if a suitable property-oriented programming (POP) chain is exploited. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this critical security risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.