CVE-2026-14602
Vulnerability Description
The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
Remote API
Discussion (0)
Add Comment
No comments yet. Be the first!