SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-59521

HIGH · CVSS 7.2 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in Real Testimonials allows for deserialization of untrusted data, leading to potential object injection attacks. This could enable an attacker to execute arbitrary code or manipulate application behavior, posing a significant risk to systems running versions up to 3.1.15. Organizations using this plugin should prioritize patching or mitigating this vulnerability to protect their applications from exploitation.

CVE
CVE-2026-59521
Severity
HIGH
CVSS
7.2
EPSS
0.29%

Original NVD Description

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.