OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-97283

CRITICAL · CVSS 9.8

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Advanced Post Manager plugin for Liquid Web / StellarWP is vulnerable to a critical deserialization of untrusted data flaw, which allows for object injection attacks. This vulnerability can lead to unauthorized access and potential remote code execution, making it imperative for all users of versions up to 4.5.5 to prioritize immediate patching. Organizations utilizing this plugin should assess their exposure and implement mitigations to safeguard against potential exploitation.

CVE
CVE-2026-97283
Severity
CRITICAL
CVSS
9.8
EPSS
N/A

Original NVD Description

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.