
🚨 Critical - WordPress Boost Plugin PHP Object Injection (CVE-2026-7637) A critical deserialization of untrusted data flaw in the "Boost" plugin for WordPress allows unauthenticated remote attackers to perform PHP Object Injection. By passing a manipulated string via the STYXKEY-BOOST_USER_LOCATION cookie, an attacker can force the application to deserialize malicious data. If a suitable Property-Oriented Programming (POP) chain exists through another installed plugin or theme, this can result in arbitrary file deletion, sensitive data retrieval, or remote code execution. 👉 Affected: WordPress Boost Plugin (PixelYourSite) <= 2.0.3 | Upgrade to version 2.0.4
Post summary
The post announces CVE‑2026‑7637, a critical deserialization flaw in WordPress Boost that allows remote PHP Object Injection and potential RCE, and recommends upgrading to version 2.0.4.

