PHP Object Injection Vulnerability in Turnkey bbPress by WeaverTheme for WordPress
CVE-2026-10035
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-10035?
The Turnkey bbPress by WeaverTheme plugin for WordPress contains a PHP Object Injection vulnerability due to the deserialization of untrusted input. This issue is present in all versions up to 1.7.1, specifically within the wvrbbp_set_to_serialized_values() function, which processes raw data from administrator-uploaded files without adequate validation. Authenticated attackers with administrator privileges can exploit this vulnerability to inject a PHP object. While the plugin does not have a present object injection chain, attackers could leverage additional themes or plugins to perform malicious actions, including code execution, file deletion, or the extraction of sensitive information.
Affected Version(s)
Turnkey bbPress by WeaverTheme 0 <= 1.7.1