PHP Object Injection Vulnerability in Kalles Addons for WordPress
CVE-2026-78572

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 August 2026

What is CVE-2026-78572?

The Kalles Addons plugin for WordPress is susceptible to PHP Object Injection due to its handling of untrusted input via deserialization. This flaw allows unauthenticated attackers to potentially inject a malicious PHP object. While the vulnerability itself does not have a direct impact without the existence of a PHP Object Pollution (POP) chain in other plugins or themes, its presence could lead to severe consequences. If a POP chain is realized through additional components on the site, attackers may exploit this vulnerability to execute arbitrary commands, delete files, or access sensitive information.

Affected Version(s)

Kalles Addons 0 <= 1.0.6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth)
.