
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23798 is a Deserialization of Untrusted Data (PHP Object Injection) vulnerability in the Blubrry PowerPress Podcasting WordPress plugin. It affects all versions up to and including 11.15.10, and was published on March 5, 2026, with the vulnerability originally reported on November 26, 2025. The flaw was discovered by Muhammad Yudha - DJ and disclosed through Patchstack's Active VDP program. It carries a CVSS v3.1 base score of 8.8 (High) (Patchstack).
The vulnerability is classified under CWE-502 (Deserialization of Untrusted Data) and is mapped to CAPEC-586 (Object Injection). An authenticated attacker with low privileges (Contributor or Developer role) can supply crafted serialized PHP data to the plugin, which is deserialized without adequate validation, enabling arbitrary object injection. If a suitable PHP Object Property (POP) chain exists within the WordPress environment, this can be leveraged to achieve remote code execution, SQL injection, path traversal, or denial of service (Patchstack).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress installation. An attacker could achieve remote code execution, unauthorized data access, data modification or deletion, and potentially full system compromise depending on available POP chains in the environment. The network-accessible attack vector and low privilege requirement increase the risk of mass exploitation across WordPress sites running the vulnerable plugin (Patchstack).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.024%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class and CVSS score are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).
__wakeup, __destruct, __toString).wp-config.php or .htaccess files.bash, curl, wget, python) following plugin interactions.The patched version is PowerPress Podcasting 11.15.11, which resolves the vulnerability — administrators should update immediately (Patchstack). Until an update can be applied, restrict access to PowerPress plugin functionality to trusted administrators only, and consider temporarily disabling the plugin if it is not actively in use. Patchstack users benefit from an automatically deployed virtual patch (mitigation rule) that blocks exploitation attempts without requiring a plugin update. Monitor WordPress logs for suspicious deserialization activity or anomalous object injection patterns.
Patchstack, which coordinated the disclosure through its Active VDP program, issued a mitigation rule for its users and rated the vulnerability as medium priority with a CVSS of 8.8, noting its potential for use in mass-exploit campaigns (Patchstack). The vulnerability was noted on VulDB and briefly referenced on social media (CVEnew on Nitter), but no significant broader community or media discussion has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."