
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32484 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the BoldGrid weForms WordPress plugin that allows PHP Object Injection. It affects weForms versions up to and including 1.6.26. The vulnerability was published on March 25, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Feedly, Patchstack).
The vulnerability stems from unsafe deserialization of user-supplied data within the weForms plugin (CWE-502), which can be exploited to perform PHP Object Injection (CAPEC-586). An attacker can craft a malicious serialized PHP object and submit it via a network request; if a suitable POP (Property-Oriented Programming) chain exists within the WordPress environment, this can lead to arbitrary code execution. Exploitation requires user interaction (e.g., a privileged user triggering the deserialization), but no special privileges are required on the attacker's part (Feedly, Patchstack).
Successful exploitation can result in complete system compromise, with high impact to confidentiality, integrity, and availability. An attacker leveraging a suitable POP chain could execute arbitrary PHP code on the server, potentially enabling unauthorized data access, file manipulation, backdoor installation, or full site takeover. The scope is limited to the affected system, but lateral movement within a shared hosting environment or connected infrastructure is possible (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.024%, indicating a low current probability of exploitation. The vulnerability has been detected by Qualys scanners (detection ID 531199) and is tracked in the ENISA vulnerability database (EUVD-2026-15828), but has not been added to the CISA Known Exploited Vulnerabilities catalog (Feedly).
unserialize() function without sanitization.O:<number>:"<classname>" in request bodies or parameters).__wakeup/__destruct method calls.shell.php, cmd.php) not associated with legitimate plugins.bash, curl, wget) indicating potential code execution following deserialization.Update the weForms plugin to a version beyond 1.6.26 as soon as a patched release becomes available from BoldGrid. If an update is not immediately available, consider temporarily deactivating the weForms plugin to eliminate the attack surface. Additionally, restrict user privileges to minimize the number of accounts that could trigger the vulnerable deserialization path, implement a Web Application Firewall (WAF) rule to detect and block serialized PHP object payloads in requests, and monitor server logs for suspicious deserialization activity (Feedly, Patchstack).
The vulnerability was included in Wordfence's weekly WordPress vulnerability report covering March 23–29, 2026, indicating it received standard industry tracking attention (Wordfence). No notable researcher commentary, vendor statements beyond the Patchstack advisory, or significant social media discussion has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."