PHP Object Injection Vulnerability in Kalles Addons for WordPress
CVE-2026-78572
8.1HIGH
What is CVE-2026-78572?
The Kalles Addons plugin for WordPress is susceptible to PHP Object Injection due to its handling of untrusted input via deserialization. This flaw allows unauthenticated attackers to potentially inject a malicious PHP object. While the vulnerability itself does not have a direct impact without the existence of a PHP Object Pollution (POP) chain in other plugins or themes, its presence could lead to severe consequences. If a POP chain is realized through additional components on the site, attackers may exploit this vulnerability to execute arbitrary commands, delete files, or access sensitive information.
Affected Version(s)
Kalles Addons 0 <= 1.0.6