#PHP Object Injection
All CosmicBytez Labs articles tagged #PHP Object Injection, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-19658 — Unauthenticated PHP Object Injection in Give Tributes for WordPress
Give Tributes ≤ 2.3.1 lets unauthenticated attackers inject a PHP object (CVSS 9.8); impact depends on a co-installed POP gadget chain.
- Security
Unlimited Elements For Elementor Plugin Vulnerable to PHP Object Injection
A missing capability check in an AJAX action lets subscriber-level users trigger PHP object injection in the Unlimited Elements For Elementor plugin.
- Security
Masteriyo LMS Deserialization Flaw Lets Low-Privilege Users Hit RCE
CVE-2026-82845 lets minimal-account WordPress users inject PHP objects through Masteriyo LMS metadata and achieve remote code execution.
- News
Critical GiveWP Flaw Lets Hackers Run Server Commands
CVE-2026-82222 chains PHP object injection and an auth-bypass bug in GiveWP, letting attackers run OS commands on 100,000+ WordPress donation sites.
- Security
Critical PHP Object Injection in FundEngine Plugin (CVE-2026-32470)
An unauthenticated PHP Object Injection flaw (CVSS 9.8) in FundEngine <= 1.7.9 allows remote attackers to execute arbitrary code without credentials.
- Security
CVE-2026-28139: Critical PHP Object Injection in Ajax Search Lite
A CVSS 9.8 unauthenticated PHP object injection flaw in Ajax Search Lite <= 4.14.4 exposes 80,000+ WordPress sites to potential remote code execution via...
- Security
CVE-2026-15962: PHP Object Injection in Fluent Forms Pro (CVSS 8.8)
A high-severity PHP Object Injection vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress allows authenticated attackers with...
- Security
CVE-2026-14637: PHP Deserialization RCE in CodeIgniter Ecommerce Bootstrap Shopping Cart
A high-severity PHP deserialization vulnerability in the kirilkirkov Ecommerce-CodeIgniter-Bootstrap allows attackers to inject malicious serialized...
- Security
CVE-2026-27053: Critical PHP Object Injection in Broadcast Live Video Plugin
A critical unauthenticated PHP Object Injection vulnerability in the Broadcast Live Video WordPress plugin (versions < 7.1.3) carries a CVSS score of 9.8...
- Security
CVE-2026-7654: PHP Object Injection RCE in WordPress Admin Columns Plugin (≤ 7.0.18)
A high-severity PHP Object Injection vulnerability in the Admin Columns WordPress plugin (versions up to 7.0.18) allows authenticated attackers to achieve…
- Security
CVE-2026-7637: WordPress Boost Plugin PHP Object Injection
The Boost plugin for WordPress versions up to 2.0.3 is vulnerable to PHP Object Injection via deserialization of the STYXKEY-BOOST_USER_LOCATION cookie,...