Deserialization Vulnerability in ConvertPlus WordPress Plugin by ConvertPro
CVE-2026-87741

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 September 2026

What is CVE-2026-87741?

The ConvertPlus plugin for WordPress contains a deserialization vulnerability that affects all versions up to and including 3.6.3. This vulnerability arises due to insufficient security checks on the style parameter used in the cp_display_preview_modal AJAX action. Specifically, the nonce validation is bypassed when the cp_admin_page_nonce parameter is omitted, allowing authenticated users with Subscriber-level access or higher to exploit the weakness. The current implementation does not filter shortcode delimiters effectively, enabling an attacker to inject malicious code that could be executed through the smile_modal_popup() function. For this exploitation to be viable, it is essential that an additional plugin or theme featuring a problematic object injection chain is also installed, as the vulnerability alone does not pose a significant risk without such a chain.

Affected Version(s)

ConvertPlus 0 <= 3.6.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad
.