Back to CVE List

CVE-2026-14602

Vulnerability Description

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
Remote API

External References

Discussion (0)

Add Comment

No comments yet. Be the first!