Critical PHP Object Injection Vulnerability in WS Form LITE Plugin
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
A critical PHP Object Injection vulnerability, CVE-2026-4703, has been identified in the WS Form LITE – Drag & Drop Form Builder plugin for WordPress, affecting all versions up to 1.10.80. Unauthenticated attackers can exploit this flaw by submitting specially crafted meta values, leading to potential deserialization of untrusted input. The vulnerability's impact is contingent on the presence of a 'POP chain' from another plugin or theme, which could allow arbitrary file deletion, sensitive data retrieval, or remote code execution. The CVSS score for this vulnerability is 9.8, indicating its critical nature. Users are urged to update to the latest version immediately and audit their WordPress installations for other vulnerable components. The vulnerability was published on August 22, 2026, and has been reported by multiple sources.
Key Points: • CVE-2026-4703 is a critical PHP Object Injection vulnerability with a CVSS score of 9.8. • The vulnerability affects all versions of the WS Form LITE plugin up to 1.10.80. • Exploitation requires a 'POP chain' from another plugin or theme, enabling severe impacts.