Sceawere
Vulnerability Detail
CVE-2026-42719UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dynamic User Directory Object Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 5h ago
- Vendor
- Sarah Giles
- Product
- Dynamic User Directory
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-10T20:16:37.030Z",
"pubdate": "2026-10-10T20:16:37.030Z",
"executiveSummary": "The Dynamic User Directory plugin for WordPress is susceptible to a PHP Object Injection vulnerability in versions 2.4 and below. This security flaw allows an authenticated subscriber-level user to perform arbitrary deserialization of untrusted input. By injecting malicious serialized objects, an attacker can manipulate application logic, potentially leading to Remote Code Execution (RCE), arbitrary file deletion, or sensitive data exposure depending on the available POP (Property-Oriented Programming) chains present within the application environment. The vulnerability stems from the unsafe use of PHP's unserialize() function on user-supplied data without adequate validation or sanitization. Given that the vulnerability is reachable by authenticated subscribers, it presents a significant risk to site integrity and confidentiality, as it bypasses standard access control mechanisms to execute arbitrary PHP logic.",
"technicalDetails": "The vulnerability resides in the core handling of user-submitted data within the Dynamic User Directory plugin. The root cause is the improper implementation of PHP's unserialize() function, which processes input that is directly controllable by a subscriber-level user. In PHP, the unserialize() function converts a string representation of an object back into a memory-resident PHP object. If the input string is maliciously crafted, an attacker can define the properties and class type of the resulting object.\nThe attack flow begins when an authenticated subscriber submits a crafted payload via an exposed endpoint or parameter that the plugin fails to sanitize. Because the application blindly passes this input to unserialize(), the PHP engine instantiates the attacker-specified class. If the application environment contains 'gadget' classes—existing classes within the plugin, WordPress core, or other installed plugins that implement magic methods such as __destruct(), __wakeup(), or __toString()—the attacker can leverage these methods to execute arbitrary code or perform unintended operations.\nBy chaining these magic methods, a threat actor can construct a POP chain to achieve post-exploitation objectives. For instance, if a gadget class has a __destruct() method that triggers a file operation or executes a system command using its properties, the attacker can hijack the control flow of the application. The scope of the impact is highly dependent on the classes declared in the target's environment; however, the ability to control object state allows for bypassing authentication checks, executing unauthorized database queries, or writing files to the web directory to gain a persistent web shell.\nThis vulnerability is classified as critical because it allows for full application compromise. It requires authentication as a subscriber, but it does not require administrative privileges, significantly lowering the barrier for exploitation. The vulnerability affects all versions of Dynamic User Directory up to and including 2.4. Because the vulnerability exists at the object-processing level, there is no inherent defense provided by the application's input filtering, as typical filters for XSS or SQL injection do not account for the structure and internal properties of serialized PHP objects."
}