Sceawere

Vulnerability Detail

CVE-2026-100506UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Spell Check Object Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
1h ago
Vendor
WP Spell Check
Product
WP Spell Check
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-05T20:17:03.760Z",
  "pubdate": "2026-10-05T20:17:03.760Z",
  "executiveSummary": "The WP Spell Check plugin for WordPress is susceptible to a Deserialization of Untrusted Data vulnerability, specifically classified as an Object Injection flaw.\nThis vulnerability exists within versions n/a through 12.1, allowing unauthenticated or low-privileged remote attackers to inject malicious serialized objects into the application.\nBy manipulating the serialized data stream, an attacker can influence the application's internal state or trigger unintended behavior during the deserialization process.\nThe primary security impact involves potential Remote Code Execution (RCE), arbitrary file modification, or unauthorized access to sensitive application data, depending on the availability of 'gadget chains' within the WordPress environment.\nSuccessful exploitation requires the attacker to submit crafted input to a vulnerable endpoint that processes serialized data without adequate validation or sanitization.\nThe vulnerability poses a severe risk to the integrity and confidentiality of the affected WordPress installation, necessitating immediate attention.",
  "technicalDetails": "The vulnerability stems from the unsafe use of PHP's unserialize() function on user-supplied input within the WP Spell Check plugin codebase.\nObject Injection occurs when untrusted data is passed to the unserialize() function, permitting the instantiation of arbitrary classes that are currently loaded in the application's scope.\nWhen an attacker provides a serialized string representing an object, the PHP engine reconstructs the object. If the object's class implements magic methods such as __wakeup(), __destruct(), or __toString(), these methods are automatically invoked by the engine during or after the deserialization process.\nThe attack flow typically involves identifying a vector where user input is serialized and passed to a vulnerable sink. The attacker crafts a malicious payload using existing classes (gadgets) found within the plugin, the WordPress core, or other active plugins/themes.\nBy chaining these gadgets, the attacker can influence the execution flow of the PHP application. For instance, an attacker could supply a serialized object that, upon destruction, invokes a file deletion method or triggers an SQL query, leading to unauthorized database manipulation.\nThe absence of integrity checks, such as cryptographic signatures or strict input allow-listing prior to deserialization, facilitates the exploitation process. The vulnerability is exploitable over the network, and the lack of authentication constraints means an attacker may trigger this logic without requiring administrative privileges, depending on the specific endpoint implementation.\nThe post-exploitation impact is limited only by the availability of accessible classes and their associated methods within the runtime environment. In highly permissive environments, this often elevates to full Remote Code Execution (RCE), allowing the adversary to gain complete control over the web server hosting the WordPress instance.\nThe vulnerability affects WP Spell Check versions from n/a through 12.1. Developers and administrators must assume that any serialized input processed by the plugin is untrusted and potentially malicious."
}
CVE-2026-100506: WP Spell Check Object Injection (HIGH Severity, CVSS: 7.2) | Sceawere