
PEACH
Un framework di isolamento del tenant
CVE-2026-15962 is a PHP Object Injection vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress, affecting all versions up to and including 6.2.6. The flaw arises from deserialization of untrusted input and allows authenticated attackers with Subscriber-level access or above to inject PHP objects. When a Property-Oriented Programming (POP) chain is present, attackers can change user passwords and potentially take over administrator accounts. The vulnerability was published on July 26, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Wordfence).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), which allows PHP object injection via crafted input submitted through the plugin's user update integration feature. Exploitation requires that user update integration is enabled and at least one user meta field is mapped — without these conditions, the attack surface does not exist. The presence of a POP chain within the plugin's codebase elevates the impact from simple object injection to privilege escalation, enabling password changes and administrator account takeover. The attack is network-based, requires only low privileges (Subscriber-level), and no user interaction (GitHub Advisory, Wordfence).
Successful exploitation allows an authenticated attacker with minimal privileges to inject malicious PHP objects, leverage the embedded POP chain to change arbitrary user passwords, and take over administrator accounts on the affected WordPress site. This results in high confidentiality, integrity, and availability impact — an attacker with administrative access can install backdoors, exfiltrate data, deface the site, or pivot to the underlying server. The scope is limited to the affected WordPress installation, but full administrative compromise effectively grants complete control over the site and its data (GitHub Advisory, Wordfence).
O:<length>:"<classname>").Update the Fluent Forms Pro Add On Pack plugin to a version newer than 6.2.6 as soon as a patched release is available (GitHub Advisory). As an immediate workaround, disable the user update integration feature within the plugin settings if it is not operationally required, and remove any mapped user meta fields to eliminate the exploitable code path. Restrict Subscriber-level account registration to trusted users only, and monitor WordPress user accounts for unauthorized password changes or new administrator accounts (Wordfence).
The vulnerability was reported by Wordfence, which assigned the CVE and published the threat intelligence entry. A brief mention was noted on Mastodon via the RedPacketSecurity account shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the initial advisory has been identified at this time (Wordfence).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."