CVE-2026-24981: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24981 is a PHP Object Injection vulnerability caused by deserialization of untrusted data in the NooTheme Visionary Core WordPress plugin (noo-visionary-core). It affects all versions through 1.4.9 and was published on March 25, 2026, with the vulnerability originally reported on December 14, 2025 by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), requiring only low-privilege (Subscriber-level) authentication with no user interaction (Patchstack).

Technical details

The root cause is improper deserialization of untrusted user-supplied data (CWE-502), which enables PHP Object Injection (CAPEC-586). An authenticated attacker with Subscriber-level privileges can craft a malicious serialized PHP object and submit it to a vulnerable endpoint in the plugin. If a suitable Property-Oriented Programming (POP) chain exists within the WordPress installation or its plugins, this can be leveraged to achieve code execution, SQL injection, path traversal, or denial of service. The vulnerability was assigned OWASP Top 10 category A3: Injection (Patchstack).

Impact

Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress site. Depending on the presence of a usable POP chain in the target environment, an attacker could achieve remote code execution, exfiltrate sensitive data, manipulate the database via SQL injection, traverse the file system, or cause a denial of service. The network-accessible attack vector and low privilege requirement increase the risk of mass exploitation across many WordPress installations (Patchstack).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.024%, reflecting a currently low probability of near-term exploitation. The vulnerability was flagged by Patchstack as high priority and expected to be targeted in mass-exploit campaigns given its low authentication requirement and high CVSS score. No threat actor attribution or CISA KEV catalog listing has been identified (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Visionary Core plugin version 1.4.9 or earlier using tools like WPScan or Shodan, or by checking the plugin's readme.txt file exposed at /wp-content/plugins/noo-visionary-core/readme.txt.
  2. Obtain low-privilege access: Register or obtain credentials for a Subscriber-level (or higher) WordPress account on the target site, as the vulnerability requires authentication.
  3. Identify the vulnerable endpoint: Locate the plugin functionality that accepts and deserializes user-supplied data (e.g., a form field, AJAX handler, or REST API endpoint within the plugin).
  4. Craft a malicious serialized payload: Using a tool such as PHPGGC, generate a serialized PHP object payload targeting a POP chain available in the WordPress environment (e.g., from other installed plugins or WordPress core).
  5. Submit the payload: Send the crafted serialized object to the vulnerable endpoint via an authenticated HTTP request.
  6. Achieve objective: If a viable POP chain is present, the deserialized object triggers the chain, potentially resulting in remote code execution, file write, SQL injection, or other impacts depending on the available gadgets (Patchstack).

Indicators of compromise

  • Network: Unusual authenticated POST requests to plugin-specific AJAX endpoints (e.g., wp-admin/admin-ajax.php) or REST API routes associated with noo-visionary-core containing serialized PHP data (strings beginning with O:, a:, s:, etc.).
  • Logs: WordPress or web server access logs showing repeated authenticated requests with abnormally large or encoded payloads to plugin endpoints; PHP error logs referencing unexpected class instantiation or unserialize() calls.
  • File System: Unexpected new PHP files or web shells in the WordPress uploads directory or plugin directories; modifications to existing plugin files.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget) if code execution is achieved via a POP chain.

Mitigation and workarounds

The vendor has released version 1.5.0 of the Visionary Core plugin, which patches this vulnerability. Site administrators should update to version 1.5.0 or later immediately via the WordPress plugin dashboard. If an immediate update is not possible, restrict access to the WordPress site to trusted users and consider temporarily deactivating the plugin. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated (Patchstack).

Community reactions

The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the period of March 16–22, 2026, indicating it received standard industry tracking. No notable individual researcher commentary or significant social media discussion has been identified beyond routine vulnerability database coverage (Wordfence).

Additional resources

  • Patchstack — Official Patchstack advisory with full vulnerability details
  • Wordfence Report — Wordfence weekly WordPress vulnerability report
  • CVE List — CVE Project official entry

Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management