
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68526 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the A WP Life Modal Popup Box WordPress plugin, affecting versions up to and including 1.6.1. It was reported on November 28, 2025, published by Patchstack on February 11, 2026, and assigned a CVSS v3.1 base score of 8.8 (High). The vulnerability allows authenticated attackers with low privileges (Contributor/Developer level) to inject malicious PHP objects via deserialization of untrusted data (Patchstack, Red Hat CVE).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), which enables PHP Object Injection (CAPEC-586). An authenticated attacker with Contributor or Developer privileges can craft a malicious serialized PHP object and submit it to the plugin, which deserializes it without adequate validation. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress environment, this can be leveraged to achieve code injection, SQL injection, path traversal, denial of service, or remote code execution. The vulnerability was discovered by Muhammad Yudha - DJ and reported to Patchstack (Patchstack).
Successful exploitation can result in complete compromise of confidentiality, integrity, and availability of the affected WordPress installation. Depending on the availability of a POP chain in the target environment, an attacker could achieve remote code execution, perform SQL injection, traverse the file system, or cause denial of service. The impact is scoped to the affected system but could enable lateral movement within a shared hosting environment or broader infrastructure (Patchstack, Red Hat CVE).
No public proof-of-concept exploit has been observed, and there is no confirmed evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. However, Patchstack notes that vulnerabilities of this class (CVSS 8.8) are frequently used in mass-exploit campaigns targeting WordPress plugins at scale. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack, Red Hat CVE).
unserialize() calls.bash, curl, wget) following plugin interactions.The patched version of the Modal Popup Box plugin is 1.6.2, which resolves the vulnerability — users should update immediately via the WordPress plugin dashboard or manually. If an immediate update is not possible, the plugin should be disabled or removed until patching is feasible, and access should be restricted to trusted administrators only. Patchstack has issued a virtual patch (WAF mitigation rule) for its users to block exploitation attempts until the plugin is updated. Additionally, implementing a Web Application Firewall with rules to detect and block PHP deserialization payloads is recommended as a defense-in-depth measure (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as part of broader WordPress plugin security coverage. Patchstack, which coordinated the disclosure, classified it as medium priority with a CVSS of 8.8 and noted its potential for use in mass-exploit campaigns targeting WordPress sites. No significant additional vendor statements or notable researcher commentary beyond the initial disclosure have been identified (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."