PHP Object Injection Vulnerability in Turnkey bbPress by WeaverTheme for WordPress
CVE-2026-10035

6.6MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 August 2026

What is CVE-2026-10035?

The Turnkey bbPress by WeaverTheme plugin for WordPress contains a PHP Object Injection vulnerability due to the deserialization of untrusted input. This issue is present in all versions up to 1.7.1, specifically within the wvrbbp_set_to_serialized_values() function, which processes raw data from administrator-uploaded files without adequate validation. Authenticated attackers with administrator privileges can exploit this vulnerability to inject a PHP object. While the plugin does not have a present object injection chain, attackers could leverage additional themes or plugins to perform malicious actions, including code execution, file deletion, or the extraction of sensitive information.

Affected Version(s)

Turnkey bbPress by WeaverTheme 0 <= 1.7.1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luk6785
.