CVE-2026-2471Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. This is due to the `BaseModel` class constructor calling `maybe_unserialize()` on all properties retrieved from the database without validation. This makes it possible for unauthenticated attackers to inject a PHP Object by submitting a double-serialized payload through any public-facing form that sends email (e.g., Contact Form 7). When the email is logged and subsequently viewed by an administrator, the malicious payload is deserialized into an arbitrary PHP object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-28); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-28: 1Mentions · 2026-03-05: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-05: 102-2803-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2471 (CVSS:7.5, HIGH) is Awaiting Analysis. The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1..https://nvd.nist.gov/vuln/detail/CVE-2026-2471 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The WP Mail Logging plugin is identified as vulnerable to PHP Object Injection (CVSS 7.5), but no proof of concept, exploit, or patch details are provided, and no active exploitation is reported.

    0000022
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2471 The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from … https://www.cve.org/CVERecord?id=CVE-2026-2471

    Post summary

    The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection via deserialization of untrusted input in all versions up to 1.15.0.

    00000106
    56.6K followersView on X

Explore more