AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-65552

CRITICAL · CVSS 9.8 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability allows for PHP Object Injection in the Export User Data plugin versions 2.2.6 and earlier, potentially enabling attackers to execute arbitrary code on affected systems. This critical flaw poses a significant risk to any organization using these versions of the plugin, as it can lead to unauthorized access and data manipulation. Organizations utilizing this plugin should prioritize immediate updates or remediation to mitigate the risk.

CVE
CVE-2026-65552
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%

Original NVD Description

Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.