WordPress Plugin Vulnerabilities

String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor

Description

The plugin does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed plugin or theme, this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution.

Proof of Concept

Affects Plugins

Fixed in 2.6.8

References

Classification

Type
OBJECT INJECTION
CWE
CVSS

Miscellaneous

Original Researcher
Raphael P. Cigana
Submitter
Raphael P. Cigana
Verified
Yes

Timeline

Publicly Published
2026-10-05 (about 2 days ago)
Added
2026-10-05 (about 1 day ago)
Last Updated
2026-10-06 (about 8 hours ago)

Other