CRITICAL
9.8 CVE-2026-4703 Published 22 Aug 2026
WordPress WS Form LITE PHP Object Injection
Worried this affects one of your servers?
The WS Form LITE plugin for WordPress is vulnerable to PHP Object Injection.
Attackers can exploit this by submitting malicious form data, allowing them to inject PHP objects.
This vulnerability has no direct impact, but if another plugin or theme with a PHP Object Injection (POP) chain is installed, it could allow attackers to delete files, retrieve sensitive data, or execute code.
Reference: CVE-2026-4703 on NVD
← Back to Security News