logo

Critical PHP Object Injection Vulnerability in WS Form LITE Plugin

ID: 0d8fcafc-a365-5c56-8307-49ac62821ddc

STIX ID: report--0d8fcafc-a365-5c56-8307-49ac62821ddc

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

...
...

A critical PHP Object Injection vulnerability (CVE-2026-4703, CVSS 9.8) was disclosed in the WS Form LITE – Drag & Drop Form Builder plugin for WordPress affecting all versions up to 1.10.80; unauthenticated attackers can exploit crafted meta values to trigger deserialization of untrusted input, and if a POP/gadget chain exists in another plugin or theme this may lead to file deletion, data exposure, or remote code execution — administrators should update the plugin and audit installations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.