以下是该漏洞描述的中文翻译: User Frontend WordPress 插件在 4.3.10 版本之前,未正确验证字段类型定义,并在渲染提交的帖子时反序列化由用户控制的后置元数据。这使得拥有编辑(Editor)级别及以上权限的用户能够注入任意 PHP 对象;若站点存在合适的 POP(Property Object Pointer,属性对象指针)链,可能导致远程代码执行(RCE)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | User Frontend | < 4.3.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | User Frontend | 0 ~ 4.3.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79996 | User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Sett | |
| CVE-2026-77701 | WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders | |
| CVE-2026-19423 | Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Pr | |
| CVE-2026-79706 | Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal | |
| CVE-2026-79995 | User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via | |
| CVE-2026-79615 | Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Dis | |
| CVE-2026-19084 | Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read | |
| CVE-2026-14567 | WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Direc | |
| CVE-2026-12514 | Shared Files < 1.7.70 - Unauthenticated Limited File Upload | |
| CVE-2026-12513 | Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal |
No comments yet