CVE-2026-5127Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form submission, combined with unconditional deserialization via maybe_unserialize() when displaying post content. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP objects, which can be leveraged to execute arbitrary code, delete arbitrary files, or perform other malicious actions if a POP chain is present on the target system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-08); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-08: 2Mentions · 2026-05-09: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-09: 105-0805-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-082
Disclosure2
2026-05-091
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5127 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrust… https://www.cve.org/CVERecord?id=CVE-2026-5127

    Post summary

    A new CVE (CVE‑2026‑5127) affecting the WordPress plugin "The User Frontend" has been announced, describing it as vulnerable to untrusted deserialization. No PoC, exploit, or remediation details are included.

    00000162
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5127 Deserialization of Untrusted Data in User Frontend AI Powered Frontend Plugin 4.3.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5127

    Post summary

    CVE-2026-5127 is a newly disclosed deserialization vulnerability affecting User Frontend AI Powered Frontend Plugin 4.3.1, with no additional evidence of PoC, exploit, active usage, patch, or false-positive status.

    0000039
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5127 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for Word… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5127 #WordPress #CyberSecurity #InfoSec

    Post summary

    The tweet announces the high‑severity CVE‑2026‑5127 affecting the User Frontend WordPress plugin, provides a link to a full analysis, and shares a CVSS score, but offers no proof‑of‑concept, exploit code, or patch information.

    0000056
    516 followersView on X

Explore more