CRITICAL
9.8 CVE-2026-66564 Published 10 Oct 2026
ShiftCV WordPress Plugin PHP Object Injection Vulnerability
Worried this affects your website?
ShiftCV versions up to and including 3.0.14 are vulnerable to an unauthenticated PHP Object Injection flaw.
Because the vulnerability requires no authentication, a remote attacker may be able to exploit it against affected installations.
Reference: CVE-2026-66564 on NVD
← Back to Security News