PT-2026-102356 · WordPress · Convertplus

·

CVE-2026-87741

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ConvertPlus versions prior to 3.6.4
Description The plugin is susceptible to deserialization of untrusted data through the style parameter of the cp display preview modal AJAX action. The issue occurs because the nonce guard is bypassed when the cp admin page nonce parameter is omitted, and no capability check is performed on the callback. Additionally, the sanitize text field() function fails to strip shortcode delimiters from the $style value before it is processed by do shortcode(). This allows authenticated attackers with Subscriber-level access or higher to inject a [smile modal] invocation, leading the smile modal popup() function to pass base64-decoded bytes to maybe unserialize() without allowed classes restrictions. This enables the injection of PHP objects. While no POP chain (a sequence of gadgets used to execute arbitrary code during deserialization) is present in the software itself, the presence of a POP chain in another installed plugin or theme could allow attackers to delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations Update the plugin to a version newer than 3.6.3. As a temporary mitigation, restrict access to the cp display preview modal AJAX action or avoid using the style parameter until the update is applied.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87741

Affected Products

Convertplus