CVE-2026-1542
Received
Received - Intake
PHP Object Injection in Super Stage WP Plugin via Unauthenticated Unserialization
Publication date: 2026-02-28
Last updated on: 2026-03-02
Assigner: WPScan
Description
Description
The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| super_stage_wp | super_stage_wp | to 1.0.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |