PT-2026-73103 · Weavertheme · Turnkey Bbpress

·

CVE-2026-10035

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Turnkey bbPress by WeaverTheme versions prior to 1.7.2
Description The plugin is susceptible to PHP Object Injection, a condition where untrusted data is passed to the unserialize() function, potentially allowing an attacker to manipulate application logic. The issue occurs within the wvrbbp set to serialized values() function, which is accessed via the wvrbbp save restore() settings-restore handler. The function processes the raw contents of a file uploaded by an administrator without proper validation. Authenticated attackers with administrator-level access or higher can exploit this to inject a PHP Object. While no POP chain (a sequence of gadgets used to achieve code execution) exists within the plugin itself, the presence of one in another installed plugin or theme could enable the deletion of arbitrary files, retrieval of sensitive data, or remote code execution.
Recommendations Update the plugin to a version newer than 1.7.1. As a temporary mitigation, restrict the use of the wvrbbp save restore() settings-restore handler.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10035

Affected Products

Turnkey Bbpress