PHP Object Injection Vulnerability in JS Archive List Plugin for WordPress
CVE-2026-2020

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 March 2026

What is CVE-2026-2020?

The JS Archive List plugin for WordPress contains a vulnerability that allows for PHP Object Injection due to the unsafe deserialization of untrusted input provided via the 'included' parameter in its shortcode. This issue affects all versions up to and including 6.1.7. Attackers with Contributor-level access or higher can exploit this vulnerability to inject malicious PHP objects. While there is no known PHP Object Propagation chain in the vulnerable software itself, if such a chain exists through other plugins or themes on the affected WordPress installation, it could enable attackers to delete arbitrary files, access sensitive information, or execute malicious code.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

JS Archive List * <= 6.1.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
Itthidej Aramsri
Waris Damkham
.