AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-65556

CRITICAL · CVSS 9.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated PHP Object Injection in WPBruiser versions up to 3.1.43, potentially enabling attackers to execute arbitrary code on affected systems. This critical flaw poses a significant risk to any website utilizing this anti-spam plugin, making it essential for administrators of these sites to prioritize immediate updates or mitigations. Organizations relying on WPBruiser for spam protection should take urgent action to secure their installations against potential exploitation.

CVE
CVE-2026-65556
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%

Original NVD Description

Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.