โ† Back to Dashboard

CVE-2026-14558

HIGH NVD
CVSS Score
7.2
Severity
HIGH
Source
NVD
Published
Aug 28, 2026
Description

The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.

View Full Details โ† Back