Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-14602

Опубликовано: 30 июл. 2026
Источник: nvd
CVSS3: 9
EPSS Низкий

Описание

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.

EPSS

Процентиль: 42%
0.00524
Низкий

9 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9
github
2 дня назад

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.

EPSS

Процентиль: 42%
0.00524
Низкий

9 Critical

CVSS3

Дефекты

CWE-94