CVE-2026-5127: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuffiles parameter during form submission, combined with unconditional deserialization via maybeunserialize() when displaying post content. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP objects, which can be leveraged to execute arbitrary code, delete arbitrary files, or perform other malicious actions if a POP chain is present on the target system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5127?
CVE-2026-5127 is classified as a high severity vulnerability due to its ability to allow authenticated users to exploit PHP Object Injection.
How do I fix CVE-2026-5127?
To fix CVE-2026-5127, update the User Frontend plugin to version 4.3.2 or later.
Who is affected by CVE-2026-5127?
Users of the User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress version 4.3.1 and earlier are affected by CVE-2026-5127.
What types of attacks can CVE-2026-5127 facilitate?
CVE-2026-5127 can facilitate attacks such as remote code execution and potentially unauthorized access to sensitive data.
Is CVE-2026-5127 a plugin-specific vulnerability?
Yes, CVE-2026-5127 specifically affects the User Frontend plugin for WordPress and does not impact the core WordPress software directly.