Deserialization Vulnerability in ConvertPlus WordPress Plugin by ConvertPro
CVE-2026-87741
What is CVE-2026-87741?
The ConvertPlus plugin for WordPress contains a deserialization vulnerability that affects all versions up to and including 3.6.3. This vulnerability arises due to insufficient security checks on the style parameter used in the cp_display_preview_modal AJAX action. Specifically, the nonce validation is bypassed when the cp_admin_page_nonce parameter is omitted, allowing authenticated users with Subscriber-level access or higher to exploit the weakness. The current implementation does not filter shortcode delimiters effectively, enabling an attacker to inject malicious code that could be executed through the smile_modal_popup() function. For this exploitation to be viable, it is essential that an additional plugin or theme featuring a problematic object injection chain is also installed, as the vulnerability alone does not pose a significant risk without such a chain.
Affected Version(s)
ConvertPlus 0 <= 3.6.3