{"id":"CVE-2026-14558","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-14558","summary":"The User Frontend  WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing…","details":"The User Frontend  WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.","published":"2026-08-28T08:16:40.327","modified":"2026-08-28T08:16:40.327","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://wpscan.com/vulnerability/217303f4-4363-46f6-8aee-8e0c1aedc271/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T08:16:40.327"}}