PHP Object Injection Vulnerability in WS Form LITE Plugin for WordPress
CVE-2026-4703
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 August 2026
What is CVE-2026-4703?
The WS Form LITE plugin for WordPress is susceptible to PHP Object Injection due to improper deserialization of untrusted data from form submissions. This vulnerability allows unauthenticated attackers to try injecting PHP objects, potentially leading to exploitation if a vulnerable plugin or theme with a PHP Object Injection (POP) chain is present. Without an existing POP chain, the vulnerability does not pose a risk, but if such a chain exists, it could result in unauthorized actions like file deletion, data retrieval, or arbitrary code execution.
Affected Version(s)
WS Form LITE β Drag & Drop Contact Form Builder 0 <= 1.10.80