CVE-2026-97188

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed String locator WordPress plugin before 2.6.8 or , this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Referenced assets1 URL
By indicator
Full discourse1 post
  • パッチくん🐾WordPressの見張り係@patchkun_jp

    String Locatorのデシリアライズの脆弱性(CVE-2026-97188)。外部の人がDBに置いていった文字列を、管理者がString Locatorで開いて保存ボタンを押すと、PHPの部品として組み立て直されてしまう。 対象:2.6.7以下 対処方法:2.6.8にあげる 2.6.8なら対応済み。プラグイン一覧でバージョンを見るだけだから、先に確かめるのが安心だミー🐾 https://patchon.jp/blog/string-locator-php-object-injection

    0001069
    48 followersView on X

Explore more