CVE-2026-1426Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortcode_check function within the Live Composer compatibility layer. This makes it possible for authenticated attackers, with Author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. Note: This vulnerability requires the Live Composer plugin to also be installed and active.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-18); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-18: 3Mentions · 2026-02-19: 1Technical Details · 2026-02-18: 302-1802-19
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-183
Disclosure3
2026-02-191
Disclosure1
Full discourse4 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-1426 - berocket - Advanced AJAX Product Filters - https://www.redpacketsecurity.com/cve-alert-cve-2026-1426-berocket-advanced-ajax-product-filters/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1426 #berocket #advanced-ajax-product-filters

    Post summary

    The tweet announces CVE-2026-1426 affecting Berocket Advanced AJAX Product Filters and links to a RedPacketSecurity advisory, but provides no further technical or exploit details.

    0000078
    3.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 HIGH severity: berocket Advanced AJAX Product Filters plugin for WordPress vulnerable to PHP Object Injection (CVE-2026-1426). Author-level access + Live Composer needed. Update ASAP! https://radar.offseq.com/threat/cve-2026-1426-cwe-502-deserialization-of-untrusted-d5d3ff22... https://t.co/utmAiRvkW1

    Post summary

    A new WordPress plugin vulnerability, CVE‑2026‑1426, has been disclosed with PHP Object Injection details requiring author‑level access and Live Composer, but no PoC, exploit, patch, or active exploitation was mentioned.

    0000037
    265 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1426 - High The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortco... https://www.thehackerwire.com/vulnerability/CVE-2026-1426/ https://t.co/7u94JM5cDd

    Post summary

    A disclosure of a PHP Object Injection vulnerability (CVE-2026-1426) affecting Advanced AJAX Product Filters for WordPress up to version 3.1.9.6.

    0000043
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1426 The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrus… https://www.cve.org/CVERecord?id=CVE-2026-1426

    Post summary

    The text announces CVE‑2026‑1426 as a PHP Object Injection flaw in the Advanced AJAX Product Filters WordPress plugin, detailing the affected versions and nature of the vulnerability, with no additional PoC, exploit, patch, or exploitation data provided.

    0000096
    56.4K followersView on X

Explore more