PHP Object Injection Vulnerability in JS Archive List Plugin for WordPress
CVE-2026-2020
What is CVE-2026-2020?
The JS Archive List plugin for WordPress contains a vulnerability that allows for PHP Object Injection due to the unsafe deserialization of untrusted input provided via the 'included' parameter in its shortcode. This issue affects all versions up to and including 6.1.7. Attackers with Contributor-level access or higher can exploit this vulnerability to inject malicious PHP objects. While there is no known PHP Object Propagation chain in the vulnerable software itself, if such a chain exists through other plugins or themes on the affected WordPress installation, it could enable attackers to delete arbitrary files, access sensitive information, or execute malicious code.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
JS Archive List * <= 6.1.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved