
CVE-2026-1542 The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a su… https://www.cve.org/CVERecord?id=CVE-2026-1542
Post summary
CVE-2026-1542 exposes the Super Stage WP WordPress plugin to unauthenticated PHP Object Injection via unserialized REQUEST data, allowing potential remote code execution.

