CVE-2026-80513

CVE-2026-80513 published: The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP c...

View full NVD advisory → ← Back to CVE watch