PHP Object Injection Vulnerability in WS Form LITE Plugin for WordPress
CVE-2026-4703

9.8CRITICAL

What is CVE-2026-4703?

The WS Form LITE plugin for WordPress is susceptible to PHP Object Injection due to improper deserialization of untrusted data from form submissions. This vulnerability allows unauthenticated attackers to try injecting PHP objects, potentially leading to exploitation if a vulnerable plugin or theme with a PHP Object Injection (POP) chain is present. Without an existing POP chain, the vulnerability does not pose a risk, but if such a chain exists, it could result in unauthorized actions like file deletion, data retrieval, or arbitrary code execution.

Affected Version(s)

WS Form LITE – Drag & Drop Contact Form Builder 0 <= 1.10.80

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn (Jitlada)
.