PT-2026-106167 · WordPress · Wp Spell Check
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Spell Check versions prior to 12.1
Description
WP Spell Check allows Object Injection due to the deserialization of untrusted data. Object Injection is a vulnerability that occurs when an application deserializes untrusted input, potentially allowing an attacker to manipulate the application logic or execute arbitrary code.
Recommendations
Update WP Spell Check to version 12.1 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Spell Check