NVD HIGH: CVE-2026-5127 — The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Members...
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form submission, combined with unconditional deserialization via maybe_unserialize() w
CVE-2026-5127