PT-2026-65780 · WordPress · Aimy Captcha-Less Form Guard

CVE-2026-65883

·

Published

2026-07-29

·

Updated

2026-08-05

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Aimy Captcha-Less Form Guard versions 18.0 through 20.0
Description PHP object injection occurs when a forged clfgd field is processed, which can lead to remote code execution. PHP object injection is a vulnerability where untrusted input is passed to the PHP unserialize() function, allowing an attacker to manipulate the object's properties and execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65883

Affected Products

Aimy Captcha-Less Form Guard