SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66620

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects versions of OptionTree up to 2.7.3, allowing for PHP Object Injection, which can lead to remote code execution and unauthorized access to sensitive data. Organizations using this plugin should prioritize patching or upgrading to mitigate potential exploitation risks. Given the high severity rating, immediate action is recommended for any systems utilizing affected versions.

CVE
CVE-2026-66620
Severity
HIGH
CVSS
7.2
EPSS
0.37%

Original NVD Description

Editor PHP Object Injection in OptionTree <= 2.7.3 versions.