
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24981 is a PHP Object Injection vulnerability caused by deserialization of untrusted data in the NooTheme Visionary Core WordPress plugin (noo-visionary-core). It affects all versions through 1.4.9 and was published on March 25, 2026, with the vulnerability originally reported on December 14, 2025 by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), requiring only low-privilege (Subscriber-level) authentication with no user interaction (Patchstack).
The root cause is improper deserialization of untrusted user-supplied data (CWE-502), which enables PHP Object Injection (CAPEC-586). An authenticated attacker with Subscriber-level privileges can craft a malicious serialized PHP object and submit it to a vulnerable endpoint in the plugin. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress installation or its plugins, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service. The vulnerability was assigned OWASP Top 10 category A3: Injection (Patchstack).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress site. Depending on the presence of a usable POP chain in the target environment, an attacker could achieve remote code execution, exfiltrate sensitive data, manipulate the database via SQL injection, traverse the file system, or cause a denial of service. The network-accessible attack vector and low privilege requirement increase the risk of mass exploitation across many WordPress installations (Patchstack).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.024%, reflecting a currently low probability of near-term exploitation. The vulnerability was flagged by Patchstack as high priority and expected to be targeted in mass-exploit campaigns given its low authentication requirement and high CVSS score. No threat actor attribution or CISA KEV catalog listing has been identified (Patchstack).
/wp-content/plugins/noo-visionary-core/readme.txt.wp-admin/admin-ajax.php) or REST API routes associated with noo-visionary-core containing serialized PHP data (strings beginning with O:, a:, s:, etc.).unserialize() calls.bash, curl, wget) if code execution is achieved via a POP chain.The vendor has released version 1.5.0 of the Visionary Core plugin, which patches this vulnerability. Site administrators should update to version 1.5.0 or later immediately via the WordPress plugin dashboard. If an immediate update is not possible, restrict access to the WordPress site to trusted users and consider temporarily deactivating the plugin. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated (Patchstack).
The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the period of March 16–22, 2026, indicating it received standard industry tracking. No notable individual researcher commentary or significant social media discussion has been identified beyond routine vulnerability database coverage (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."