OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103348

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The WP Ultimate Exporter plugin by Smackcoders Inc. is vulnerable to deserialization of untrusted data, allowing for object injection attacks. This could enable an attacker to execute arbitrary code or manipulate the application’s behavior, potentially compromising the integrity of the WordPress site. Organizations using versions of the plugin up to 3.0 should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-103348
Severity
HIGH
CVSS
7.2
EPSS
0.37%

Original NVD Description

Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.