CyberRota Analysis
AI-GeneratedThe WP Ultimate Exporter plugin by Smackcoders Inc. is vulnerable to deserialization of untrusted data, allowing for object injection attacks. This could enable an attacker to execute arbitrary code or manipulate the application’s behavior, potentially compromising the integrity of the WordPress site. Organizations using versions of the plugin up to 3.0 should prioritize patching this vulnerability to mitigate the risk of exploitation.
CVE
CVE-2026-103348
Severity
HIGH
CVSS
7.2
EPSS
0.37%
Original NVD Description
Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.