CVE-2026-0551Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-08-23); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-08-23: 4Mentions · 2026-08-24: 1Technical Details · 2026-08-23: 4Technical Details · 2026-08-24: 108-2308-24
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-234
Disclosure4
2026-08-241
Disclosure1
Full discourse5 posts
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Disclosure

    ページをパスワードで隠すプラグインPPWPに、PHPオブジェクトインジェクションの脆弱性(CVE-2026-0551)をWordfenceが公開したモー🐮 隠すために入れた部品が、そのまま入口になるモー🐄

    Post summary

    Wordfence disclosed CVE-2026-0551, a PHP object injection flaw in the PPWP password‑hide plugin, without mentioning any PoC, exploitation, or mitigation.

    00020270
    913 followersView on X
  • LoreleiWeb@LoreleiWeb
    Disclosure

    🆕👉 PPWP Password Protect Pages https://wpdeeply.com/ppwp-password-protect-pages-1-9-18-php-object-injection/ #loreleiweb Wordfence Intelligence published CVE-2026-0551 on August 22, 2026 for PPWP – Password Protect Pages, a WordPress content-protection plugin with 30,000+ active installations. The vulnerability is a PHP Object… https://t.co/CrX2y1RB2W

    Post summary

    Wordfence Intelligence has published a new CVE (CVE-2026-0551) for the PPWP WordPress plugin, identifying a PHP Object Injection flaw; no PoC, exploit, or patch details are provided in the tweet.

    00110538
    85.9K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    WordPress sites using PPWP Password Protect Pages plugin (≤1.9.18) have a CVSS 8.8 vulnerability (CVE-2026-0551). Verify and update if in use: https://nvd.nist.gov/vuln/detail/CVE-2026-0551 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/7exjlrNL70

    Post summary

    A short tweet alerts WordPress users to a CVSS 8.8 vulnerability (CVE‑2026‑0551) affecting the PPWP Password Protect Pages plugin (≤1.9.18) and directs them to the NVD page for further information.

    0000033
    93 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-0551 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrust… https://www.cve.org/CVERecord?id=CVE-2026-0551 ----- Traducción: CVE-2026-0551 El … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑0551 as a PHP Object Injection flaw in the PPWP – Password Protect Pages WordPress plugin (versions ≤1.9.18) but offers no evidence of exploitation, PoC, or mitigation.

    0000039
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0551 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrust… https://www.cve.org/CVERecord?id=CVE-2026-0551

    Post summary

    The PPWP WordPress plugin (v1.9.18 and earlier) is vulnerable to PHP Object Injection via deserialization of untrusted data, as identified by CVE‑2026‑0551.

    00000883
    58.0K followersView on X

Explore more