Ostorlab[verified]@OstorlabSecDisclosure
The post announces a critical PHP Object Injection flaw in the Contact Form Entries plugin, provides a detailed exploitation chain, includes mitigation steps, and links to a comprehensive technical write-up.
Quttera - eCommerce Security[verified]@MNovofastovskyPatch
A critical PHP Object Injection flaw (CVE‑2026‑2599) affects several popular WordPress form plugins; the post urges users to update immediately to mitigate the high‑severity vulnerability.
CVEFind.com@CveFindComGeneral
The tweet announces CVE-2026-2599, a PHP Object Injection flaw in several WordPress plugins that could enable code execution via a POP chain, but it provides no proof of concept, exploit code, patch, or evidence of active exploitation.
CERT-PY@CERTpyDisclosure
The tweet announces the existence of CVE-2026-2599, a vulnerability in a WordPress plugin, and directs readers to an external source for additional details.
CVE@CVEnewDisclosure
The statement announces CVE‑2026‑2599, a PHP Object Injection flaw in WordPress form plugins up to v1.4.7, providing basic technical details but no evidence of exploitation or remediation.
The Hacker Wire@TheHackerWireDisclosure
CVE‑2026‑2599 exposes PHP Object Injection via deserialization in WordPress form plugins (Contact Form 7, WPforms, Elementor Forms) up to version 1.4.7, with critical severity announced but no exploit, patch, or active use reported.