CVE-2026-2020Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This is due to the deserialization of untrusted input supplied via the 'included' parameter of the plugin's shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-07); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-07: 4Mentions · 2026-03-12: 1Technical Details · 2026-03-07: 3Technical Details · 2026-03-12: 103-0703-12
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-074
Disclosure4
2026-03-121
Disclosure1
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2020 PHP Object Injection in WordPress JS Archive List Plugin via Shortcode Attribute https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2020

    Post summary

    The post announces a CVE‑2026‑2020 PHP Object Injection vulnerability affecting the WordPress JS Archive List Plugin via a shortcode attribute, without details on PoC, exploitation, or patches.

    0101074
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2020 (CVSS:7.5, HIGH) is Awaiting Analysis. The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1..https://nvd.nist.gov/vuln/detail/CVE-2026-2020 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces that CVE-2026-2020 affects the JS Archive List WordPress plugin via PHP Object Injection, with a CVSS 7.5 score, and notes that it is awaiting analysis without mentioning any PoC, exploit, patch, or active exploitation evidence.

    0000019
    172 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2020 The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This … https://www.cve.org/CVERecord?id=CVE-2026-2020 ----- Traducción: CVE-2026-2020 El … http://infoflow.cloud`

    Post summary

    CVE‑2026‑2020 reveals a PHP Object Injection flaw in the JS Archive List WordPress plugin (up to v6.1.7) via the 'included' shortcode. No PoC, exploit, patch, or active exploitation is reported.

    0000040
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2020 The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This … https://www.cve.org/CVERecord?id=CVE-2026-2020

    Post summary

    The text reports a PHP Object Injection vulnerability discovered in the JS Archive List WordPress plugin, noting the affected versions but providing no proof of exploitation or mitigation.

    00000174
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-2020 - skatox - JS Archive List - https://www.redpacketsecurity.com/cve-alert-cve-2026-2020-skatox-js-archive-list/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2020 #skatox #js-archive-list

    Post summary

    The post announces CVE-2026-2020 (skatox – JS Archive List) via a RedPacket Security alert link, but provides no further technical or mitigation details.

    0000096
    3.5K followersView on X

Explore more