PT-2026-22463 · WordPress · Super Stage Wp

Publicado

2026-02-28

·

Atualizado

2026-02-28

·

CVE-2026-1542

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Super Stage WP WordPress plugin versions through 1.0.1
Description The software allows unauthenticated users to perform PHP Object Injection. This is possible because the software unserializes user input via REQUEST when a suitable gadget is present. The issue could allow for malicious code execution.
Recommendations Update the Super Stage WP WordPress plugin to a version later than 1.0.1.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1542

Produtos afetados

Super Stage Wp