Critical PHP Object Injection in FundEngine Plugin (CVE-2026-32470)
ID: 0410379a-9ae3-58e0-9c30-68994fefaf1a
STIX ID: report--0410379a-9ae3-58e0-9c30-68994fefaf1a
Feed Name: CosmicBytez Labs
A critical (CVSS 9.8) unauthenticated PHP Object Injection vulnerability (CVE-2026-32470) in the FundEngine WordPress plugin (<=1.7.9) allows attackers to submit crafted serialized PHP objects that may lead to remote code execution, file manipulation, data exfiltration, and full site compromise when a suitable POP chain is present; the report details the attack chain, indicators (serialized payload patterns, unexpected PHP files, new admin accounts, outbound connections), and remediation steps including patching or removing the plugin, auditing for POP chains, scanning for compromise, rotating credentials, and deploying WAF protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
