Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces a CVE‑2026‑2020 PHP Object Injection vulnerability affecting the WordPress JS Archive List Plugin via a shortcode attribute, without details on PoC, exploitation, or patches.
CRAC Learning - Tech@cracbotDisclosure
The post announces that CVE-2026-2020 affects the JS Archive List WordPress plugin via PHP Object Injection, with a CVSS 7.5 score, and notes that it is awaiting analysis without mentioning any PoC, exploit, patch, or active exploitation evidence.
Infoflowcloud@infoflowcloudDisclosure
CVE‑2026‑2020 reveals a PHP Object Injection flaw in the JS Archive List WordPress plugin (up to v6.1.7) via the 'included' shortcode. No PoC, exploit, patch, or active exploitation is reported.
CVE@CVEnewDisclosure
The text reports a PHP Object Injection vulnerability discovered in the JS Archive List WordPress plugin, noting the affected versions but providing no proof of exploitation or mitigation.
RedPacket Security@RedPacketSecDisclosure
The post announces CVE-2026-2020 (skatox – JS Archive List) via a RedPacket Security alert link, but provides no further technical or mitigation details.