SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-78572

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

The Kalles Addons plugin for WordPress is susceptible to PHP Object Injection due to the deserialization of untrusted input, affecting all versions up to 1.0.6. While the vulnerability itself does not pose a direct threat, it can be exploited if a vulnerable plugin or theme containing a PHP Object Injection (POP) chain is present, potentially allowing attackers to delete files, access sensitive data, or execute arbitrary code. WordPress site administrators using this plugin, especially those with additional plugins or themes that may contain a POP chain, should prioritize patching to mitigate the risk.

CVE
CVE-2026-78572
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.