PHP Object Injection Vulnerability in TaxoPress by WordPress
CVE-2026-74012
8.8HIGH
What is CVE-2026-74012?
The TaxoPress plugin for WordPress is affected by a PHP Object Injection vulnerability that allows attackers to exploit the application by sending specially crafted input to the affected component. This flaw exists in versions of TaxoPress up to 3.51.0. Successful exploitation could potentially lead to remote code execution or unauthorized access, posing a significant risk to the integrity and confidentiality of the application and its data.
Affected Version(s)
TaxoPress <= 3.51.0