logo

CVE-2026-27053: Critical PHP Object Injection in Broadcast Live Video Plugin

ID: ab008494-2a64-5573-b2f7-c8148828d3e7

STIX ID: report--ab008494-2a64-5573-b2f7-c8148828d3e7

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-06-17

...
...

A critical unauthenticated PHP Object Injection (CVE-2026-27053, CVSS 9.8) was disclosed in the Broadcast Live Video WordPress plugin (all versions prior to 7.1.3), allowing remote attackers to supply serialized PHP objects that are deserialized by the plugin and can lead to RCE, file deletion, SSRF, or data exfiltration; administrators should immediately update to 7.1.3 or remove the plugin and review logs for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.