
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24378 is a PHP Object Injection vulnerability (Deserialization of Untrusted Data) in the Metagauss EventPrime WordPress plugin, affecting all versions through 4.2.8.0. The vulnerability was reported by researcher Phat RiO on December 19, 2025, and publicly disclosed by Patchstack on March 17, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical), requiring no authentication or user interaction for exploitation (Patchstack).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), enabling PHP Object Injection (CAPEC-586). When the EventPrime plugin deserializes attacker-controlled input without proper validation, an adversary can instantiate arbitrary PHP objects on the server. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress environment or installed plugins, this can be escalated to remote code execution, SQL injection, path traversal, or denial of service. The attack is network-accessible, requires no privileges, and no user interaction (Patchstack).
Successful exploitation could result in complete compromise of the affected WordPress installation, with high impact to confidentiality, integrity, and availability. Depending on available POP chains in the environment, attackers may achieve remote code execution, unauthorized database access via SQL injection, arbitrary file read/write via path traversal, or service disruption. The unauthenticated, network-accessible nature of the flaw makes it suitable for mass-exploitation campaigns targeting large numbers of WordPress sites regardless of their traffic or popularity (Patchstack).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation. The EPSS score is approximately 0.024%, reflecting low current exploitation probability. The vulnerability was detected by Qualys scanners and is tracked in the ENISA EUVD as EUVD-2026-15573. Despite the absence of active exploitation, the critical CVSS score and unauthenticated attack vector make it a high-priority target for future mass-exploit campaigns (Patchstack).
__wakeup, __destruct, etc.) that form the POP chain.O:, a:, or s: patterns); unexpected outbound connections from the web server to external IPs.eval, base64_decode, system, or passthru functions).bash, curl, wget, python) not associated with normal WordPress operation.The vendor has released version 4.2.8.1 of the EventPrime plugin, which patches this vulnerability. All WordPress site operators running EventPrime version 4.2.8.0 or earlier should upgrade to 4.2.8.1 or later immediately. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. If immediate upgrading is not possible, consider temporarily deactivating the plugin and consulting your hosting provider (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of March 16–22, 2026, highlighting it as a notable security issue for WordPress site operators (Wordfence Blog). VulnDB also tracked the vulnerability shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the initial Patchstack advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."