CVE-2026-103348
Received Received - Intake

Deserialization of Untrusted Data in WP Ultimate Exporter

Vulnerability report for CVE-2026-103348, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Patchstack

Description

Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Smackcoders Inc. WP Ultimate Exporter 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a PHP Object Injection vulnerability in the WP Ultimate Exporter WordPress plugin versions 3.0 and below. It allows attackers to inject malicious objects during deserialization, potentially leading to remote code execution or other harmful actions on the server.

Detection Guidance

Detecting this vulnerability requires checking the installed version of the WP Ultimate Exporter plugin. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files in the /wp-content/plugins/wp-ultimate-exporter/ directory for version details. If the version is 3.0 or below, the system is vulnerable.

Impact Analysis

Attackers could exploit this to execute arbitrary code on your server, steal sensitive data, or take control of your WordPress site. The CVSS score of 7.2 indicates a high risk of exploitation, especially in widespread attacks targeting multiple websites.

Compliance Impact

This vulnerability could lead to unauthorized data access or breaches, violating GDPR (data protection) and HIPAA (health data privacy) requirements. Organizations may face legal penalties, fines, or reputational damage if exploited.

Mitigation Strategies

Immediately update the WP Ultimate Exporter plugin to version 3.1 or later. If updating is not possible, apply mitigation measures provided by Patchstack or disable the plugin until an update is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103348. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart