Critical PHP Object Injection Vulnerability in WS Form LITE Plugin

Critical PHP Object Injection Vulnerability in WS Form LITE Plugin

First seen 24 Aug 2026, 02:14 UTC Theexploitdesk.Technvd.nist.gov 76% similarity 78.0

Article Content

Browse articles
ThreatCluster

A critical PHP Object Injection vulnerability, CVE-2026-4703, has been identified in the WS Form LITE – Drag & Drop Form Builder plugin for WordPress, affecting all versions up to 1.10.80. Unauthenticated attackers can exploit this flaw by submitting specially crafted meta values, leading to potential deserialization of untrusted input. The vulnerability's impact is contingent on the presence of a 'POP chain' from another plugin or theme, which could allow arbitrary file deletion, sensitive data retrieval, or remote code execution. The CVSS score for this vulnerability is 9.8, indicating its critical nature. Users are urged to update to the latest version immediately and audit their WordPress installations for other vulnerable components. The vulnerability was published on August 22, 2026, and has been reported by multiple sources.

Key Points: • CVE-2026-4703 is a critical PHP Object Injection vulnerability with a CVSS score of 9.8. • The vulnerability affects all versions of the WS Form LITE plugin up to 1.10.80. • Exploitation requires a 'POP chain' from another plugin or theme, enabling severe impacts.

ThreatCluster AI How this analysis works

Timeline

2026-08-22
CVE-2026-4703 published
The CVE record for the critical vulnerability in WS Form LITE was published, detailing the PHP Object Injection flaw.
nvd.nist.gov
2026-08-23
Vulnerability reported by The Exploit Desk
The Exploit Desk published an article detailing the critical nature of CVE-2026-4703 and its potential impacts.
Theexploitdesk.Tech
2026-08-24
Security advisory issued
Users are advised to update the WS Form LITE plugin and audit their WordPress installations for vulnerabilities.
Theexploitdesk.Tech

Community

Browse all →

Tracked Entities in This Story