Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97188 1 Wordpress-extensions 1 String Locator 2026-10-09 8.8 High
The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed String locator WordPress plugin before 2.6.8 or , this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution.