CVE-2026-42719: WordPress Dynamic User Directory plugin <= 2.4 - PHP Object Injection vulnerability
Published Oct 10, 2026
·Updated
Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
Affected Software
1 affected component
WordPress Dynamic User Directory<=2.4
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as subscriber PHP object injection, indicating that a user with the WordPress Subscriber role can exploit it. The CVSS vector lists no additional privileges required, no user interaction, and network-based reachability.
2
What versions are affected?
Dynamic User Directory versions 2.4 and earlier are identified as affected.
3
What is the potential impact?
The vulnerability is rated critical with a 9.8 CVSS score and can affect confidentiality, integrity, and availability at high impact levels.