CVE-2026-7637Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-20: 2Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-20: 205-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - WordPress Boost Plugin PHP Object Injection (CVE-2026-7637) A critical deserialization of untrusted data flaw in the "Boost" plugin for WordPress allows unauthenticated remote attackers to perform PHP Object Injection. By passing a manipulated string via the STYXKEY-BOOST_USER_LOCATION cookie, an attacker can force the application to deserialize malicious data. If a suitable Property-Oriented Programming (POP) chain exists through another installed plugin or theme, this can result in arbitrary file deletion, sensitive data retrieval, or remote code execution. 👉 Affected: WordPress Boost Plugin (PixelYourSite) <= 2.0.3 | Upgrade to version 2.0.4

    Post summary

    The post announces CVE‑2026‑7637, a critical deserialization flaw in WordPress Boost that allows remote PHP Object Injection and potential RCE, and recommends upgrading to version 2.0.4.

    00030167
    255 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7637 The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST… https://www.cve.org/CVERecord?id=CVE-2026-7637

    Post summary

    The text announces CVE-2026-7637, stating that the Boost WordPress plugin is vulnerable to PHP Object Injection due to deserialization of untrusted input.

    00020149
    57.8K followersView on X

Explore more