CyberRota Analysis
AI-GeneratedWP Spell Check versions up to 12.1 are vulnerable to a deserialization of untrusted data flaw that allows for object injection, potentially enabling attackers to execute arbitrary code. Organizations using this plugin should prioritize remediation to mitigate the risk of exploitation, which could lead to unauthorized access or manipulation of their systems.
CVE
CVE-2026-100506
Severity
HIGH
CVSS
7.2
EPSS
0.37%
Original NVD Description
Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.