OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-97256

HIGH · CVSS 7.2 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Page Builder by SiteOrigin versions up to 2.36.0 are vulnerable to PHP Object Injection, which could allow an attacker to execute arbitrary code on the server. This high-severity vulnerability poses a significant risk to any sites utilizing the affected plugin, particularly those with inadequate input validation. Organizations using this plugin should prioritize immediate updates or mitigations to safeguard against potential exploitation.

CVE
CVE-2026-97256
Severity
HIGH
CVSS
7.2
EPSS
0.30%

Original NVD Description

Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.