← Back to the live CVE advisory feed

CVE-2026-19116: User Frontend

Severity
8.8 (HIGH)
Affected versions
0 through before 4.3.11
Fixed version
4.3.11
Patch status
Patched
Published
2026-09-02T06:17:16.643
Modified
2026-09-02T11:17:19.117

Why it matters

This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Check whether the affected WordPress plugin or theme is installed.
  • Update, disable, or remove the affected component if present.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.

Technical summary

The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 02, 2026 04:00 PM UTC
455 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-76657
fabric composer
Reporter: SECURITY-ALERT
10
CRITICAL
VIEW RECORD
CVE-2026-76658
fabric composer
Reporter: SECURITY-ALERT
10
CRITICAL
VIEW RECORD
CVE-2026-83548
SMA1000
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-4357
Embed HTML5 Game
Reporter: CONTACT
10
CRITICAL
VIEW RECORD
CVE-2026-77009
WatchMan-Site7
Reporter: CONTACT
9.9
CRITICAL
VIEW RECORD
CVE-2026-73749
AOS-CX
Reporter: SECURITY-ALERT
9.8
CRITICAL
VIEW RECORD
CVE-2026-84372
predis PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-9055
Booking for Appointments and Events Calendar – Amelia
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-78657
SigmaForms Pro – AI Generated Forms
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-81294
Authorizer PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2025-9314
Developer Tools
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-19766
Fabric Composer
Reporter: SECURITY-ALERT
9.6
CRITICAL
VIEW RECORD
CVE-2026-84333
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
9.6
CRITICAL
VIEW RECORD
CVE-2026-84352
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
9.6
CRITICAL
VIEW RECORD
CVE-2026-84353
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
9.6
CRITICAL
VIEW RECORD
CVE-2026-84354
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
9.6
CRITICAL
VIEW RECORD
CVE-2023-54391
Proxmox Virtual Environment (VE) PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-84479
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-84480
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-84695
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-84696
PS3111-S11 Controller Firmware
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-84699
Team Password Manager PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-81286
WCFM Marketplace PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-84795
cms PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-18931
Talassoft Industrial Management Software
Reporter: ILETISIM
9.1
CRITICAL
VIEW RECORD
CVE-2026-79687
PowerStore 500T
Reporter: SECURITY_ALERT
9
CRITICAL
VIEW RECORD
CVE-2026-73700
Fabric Composer
Reporter: SECURITY-ALERT
9
CRITICAL
VIEW RECORD
CVE-2026-73701
Fabric Composer
Reporter: SECURITY-ALERT
9
CRITICAL
VIEW RECORD
CVE-2026-75604
next.js PATCH
Reporter: SECURITY-ADVISORIES
9
CRITICAL
VIEW RECORD
CVE-2026-84324
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
9
CRITICAL
VIEW RECORD
CVE-2026-82955
Eclipse aeriOS
Reporter: EMO
9
CRITICAL
VIEW RECORD
CVE-2026-10195
FS Poster – WordPress Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest]
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-58567
Product identification pending
Reporter: SECURITY_ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-79682
Product identification pending
Reporter: SECURITY_ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-84268
Product identification pending
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-58566
Product identification pending
Reporter: SECURITY_ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-72649
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-73702
fabric composer
Reporter: SECURITY-ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-73703
fabric composer
Reporter: SECURITY-ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-73704
fabric composer
Reporter: SECURITY-ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-73705
fabric composer
Reporter: SECURITY-ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-73750
Product identification pending
Reporter: SECURITY-ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-73751
Product identification pending
Reporter: SECURITY-ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-73752
Product identification pending
Reporter: SECURITY-ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-73753
Product identification pending
Reporter: SECURITY-ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-73782
Product identification pending
Reporter: SECURITY-ALERT
8.8
HIGH
VIEW RECORD
CVE-2026-84326
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
8.8
HIGH
VIEW RECORD
CVE-2026-84347
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
8.8
HIGH
VIEW RECORD
CVE-2026-84350
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
8.8
HIGH
VIEW RECORD
CVE-2026-84700
pikiwidb
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-14357
DevKit Pro
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-19116
User Frontend PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-81737
FAQ Builder AYS PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-81807
Simple Ajax Chat PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-14828
Product identification pending PATCH
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-81283
WP User Frontend PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-81769
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-81772
Ninja Forms – Layout & Styles
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-84764
Simply Schedule Appointments PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-84770
Mang Board WP PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-84202
modelscope
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2024-7952
Product identification pending
Reporter: PSIRT
8.7
HIGH
VIEW RECORD
CVE-2024-7953
Product identification pending
Reporter: PSIRT
8.7
HIGH
VIEW RECORD
CVE-2026-84304
grpc-go PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-71981
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84208
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84476
AVideo
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84482
AVideo
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84694
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84702
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84484
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84485
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84715
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84796
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84801
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-79989
cms
Reporter: 7004884B-51E2-48E8-B4A2-5CA29E80453E
8.7
HIGH
VIEW RECORD
CVE-2026-79990
cms
Reporter: 7004884B-51E2-48E8-B4A2-5CA29E80453E
8.7
HIGH
VIEW RECORD
CVE-2026-84203
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-73706
fabric composer
Reporter: SECURITY-ALERT
8.6
HIGH
VIEW RECORD
CVE-2026-19754
Product identification pending
Reporter: HELP
8.6
HIGH
VIEW RECORD
CVE-2024-35585
Product identification pending PATCH
Reporter: CVE
8.6
HIGH
VIEW RECORD
CVE-2026-84803
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-83551
sagemaker-python-sdk
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
8.5
HIGH
VIEW RECORD
CVE-2026-45221
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-73707
fabric composer
Reporter: SECURITY-ALERT
8.5
HIGH
VIEW RECORD
CVE-2026-73781
Product identification pending
Reporter: SECURITY-ALERT
8.4
HIGH
VIEW RECORD
CVE-2026-63137
kibana
Reporter: SECURITY
8.3
HIGH
VIEW RECORD
CVE-2026-73708
fabric composer
Reporter: SECURITY-ALERT
8.3
HIGH
VIEW RECORD
CVE-2026-73709
fabric composer
Reporter: SECURITY-ALERT
8.3
HIGH
VIEW RECORD
CVE-2026-73780
Product identification pending
Reporter: SECURITY-ALERT
8.3
HIGH
VIEW RECORD
CVE-2026-84335
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
8.3
HIGH
VIEW RECORD
CVE-2026-84349
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
8.3
HIGH
VIEW RECORD
CVE-2026-84351
Product identification pending PATCH
Reporter: CHROME-CVE-ADMIN
8.3
HIGH
VIEW RECORD
CVE-2026-73710
Product identification pending
Reporter: SECURITY-ALERT
8.2
HIGH
VIEW RECORD
CVE-2026-73779
Product identification pending
Reporter: SECURITY-ALERT
8.2
HIGH
VIEW RECORD
CVE-2026-84370
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-18730
Product identification pending PATCH
Reporter: PRODUCT-CNA
8.2
HIGH
VIEW RECORD
CVE-2025-15485
Auto x LINE
Reporter: CONTACT
8.2
HIGH
VIEW RECORD
CVE-2026-73711
Product identification pending
Reporter: SECURITY-ALERT
8.1
HIGH
VIEW RECORD
CVE-2026-73712
Product identification pending
Reporter: SECURITY-ALERT
8.1
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.