WordPress Plugin Vulnerabilities

WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder

Description

The plugin does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.

Proof of Concept

Affects Plugins

Fixed in 4.3.10

References

Classification

Type
OBJECT INJECTION
CWE
CVSS

Miscellaneous

Original Researcher
Hijun Kim
Submitter
Hijun Kim
Verified
Yes

Timeline

Publicly Published
2026-08-26 (about 2 days ago)
Added
2026-08-26 (about 1 day ago)
Last Updated
2026-08-26 (about 1 day ago)

Other