The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
History

Mon, 02 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Super Stage Wp
Super Stage Wp super Stage Wp
Wordpress
Wordpress wordpress
Vendors & Products Super Stage Wp
Super Stage Wp super Stage Wp
Wordpress
Wordpress wordpress

Sat, 28 Feb 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Title Super Stage WP <= 1.0.1 - Unauthenticated PHP Object Injection
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-02-28T06:00:08.933Z

Updated: 2026-03-02T14:04:37.368Z

Reserved: 2026-01-28T15:00:06.802Z

Link: CVE-2026-1542

cve-icon Vulnrichment

Updated: 2026-03-02T14:04:33.556Z

cve-icon NVD

Status : Received

Published: 2026-02-28T06:16:02.080

Modified: 2026-03-02T15:16:32.057

Link: CVE-2026-1542

cve-icon Redhat

No data.