Unauthenticated PHP Object Injection Vulnerability in FundEngine by WordPress
CVE-2026-73993
9.8CRITICAL
What is CVE-2026-73993?
The FundEngine plugin for WordPress is susceptible to an unauthenticated PHP Object Injection vulnerability in versions 1.7.9 and earlier. This flaw allows an attacker to exploit the system without requiring prior authentication, potentially leading to remote code execution or other harmful actions. Users of affected versions are encouraged to update to the latest version to mitigate risks.
Affected Version(s)
FundEngine <= 1.7.9