OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100506

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

WP Spell Check versions up to 12.1 are vulnerable to a deserialization of untrusted data flaw that allows for object injection, potentially enabling attackers to execute arbitrary code. Organizations using this plugin should prioritize remediation to mitigate the risk of exploitation, which could lead to unauthorized access or manipulation of their systems.

CVE
CVE-2026-100506
Severity
HIGH
CVSS
7.2
EPSS
0.37%

Original NVD Description

Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.