CYBERHAWK / CVE / CVE-2026-5127

CVE-2026-5127

User Frontend WordPress Plugin

HIGH CVSS 8.8 vibe

The flaw

Deserialization vulnerability allows authenticated remote code execution.

What to do

Update to version 4.3.2 or later

▸ Scan my repo for CVE-2026-5127

References

First seen 2026-05-08 · Tracked by PickBits CyberHawk · Weekly CVE digest