
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78572 is a PHP Object Injection vulnerability in the Kalles Addons plugin for WordPress, affecting all versions up to and including 1.0.6. It was discovered by João Pedro S Alcântara (Kinorth), reported on February 5, 2026, and published to the GitHub Advisory Database on August 25, 2026. The vulnerability allows unauthenticated attackers to inject arbitrary PHP objects via deserialization of untrusted input, with actual impact contingent on the presence of a usable POP (Property-Oriented Programming) chain from another installed plugin or theme. It carries a CVSS v3.1 base score of 8.1 (High) per NVD, while Patchstack rates it 9.8 (Critical) (GitHub Advisory, Patchstack).
The root cause is improper deserialization of untrusted user-supplied input (CWE-502), which allows an unauthenticated remote attacker to inject a PHP object into the application over the network. The attack vector is network-based with high complexity, requiring no privileges or user interaction, but exploitation depends on the presence of a compatible POP chain in another installed plugin or theme on the same WordPress site. If such a gadget chain exists, the injected object can be leveraged to trigger arbitrary actions defined by the chain, such as file deletion, data exfiltration, or remote code execution. No specific technical write-up or public proof-of-concept code has been identified at this time (GitHub Advisory, Patchstack).
If a compatible POP chain is present via another installed plugin or theme, successful exploitation could allow an unauthenticated attacker to delete arbitrary files, retrieve sensitive data, or execute arbitrary code on the affected WordPress server. This could result in full site compromise, including unauthorized access to the database, exposure of credentials or user data, and potential lateral movement within the hosting environment. In the absence of a usable POP chain, the vulnerability has no direct impact (GitHub Advisory, Patchstack).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The EPSS score is 0.0, reflecting a currently low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on the co-presence of a POP chain from another plugin or theme, which raises the effective attack complexity (GitHub Advisory, Patchstack).
__wakeup, __destruct), executing the attacker's intended action — such as writing a web shell, deleting files, or exfiltrating data — depending on the chain available (GitHub Advisory, Patchstack).O:<length>:"<classname>" patterns in request bodies or parameters).bash, curl, wget) indicating potential code execution via a triggered POP chain.Site administrators should update the Kalles Addons plugin to a version newer than 1.0.6 as soon as a patched release becomes available. In the interim, Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts for subscribers of their service. Additionally, administrators should audit all installed plugins and themes for known POP chains that could be leveraged in conjunction with this vulnerability, and remove or update any that are unnecessary or outdated. Implementing a web application firewall (WAF) rule to block serialized PHP object payloads in HTTP requests is also recommended as a defense-in-depth measure (GitHub Advisory, Patchstack).
Patchstack, which credited researcher João Pedro S Alcântara (Kinorth) with the discovery, has classified this as high priority and issued a virtual mitigation rule ahead of an official patch. Wordfence has also catalogued the vulnerability in their threat intelligence database. No significant broader media coverage or notable social media commentary has been identified at this time (Patchstack, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."