Sceawere

Vulnerability Detail

CVE-2026-97283UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Advanced Post Manager Object Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
2h ago
Vendor
Liquid Web / StellarWP
Product
Advanced Post Manager
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-05T19:17:27.133Z",
  "pubdate": "2026-10-05T19:17:27.133Z",
  "executiveSummary": "The Advanced Post Manager plugin for WordPress, developed by Liquid Web / StellarWP, is vulnerable to an Object Injection flaw arising from the insecure deserialization of untrusted data.\nThis vulnerability exists within versions n/a through 4.5.5, posing a critical security risk to websites utilizing the plugin.\nAn unauthenticated or authenticated attacker can leverage this flaw to inject serialized PHP objects into the application, potentially leading to Remote Code Execution (RCE), arbitrary file deletion, or sensitive data access depending on the presence of available 'gadget chains' within the WordPress environment.\nThe vulnerability occurs because the plugin fails to properly validate or sanitize serialized input before processing it through PHP's unserialize() function.\nThe impact is significant, as successful exploitation can lead to full site compromise. Because deserialization occurs upon data processing, the risk is elevated for any component that passes user-controlled input to this vulnerable function.",
  "technicalDetails": "The core vulnerability is identified as a PHP Object Injection flaw resulting from the insecure use of the unserialize() function on untrusted user-supplied data. In PHP, the unserialize() function can be leveraged by attackers to instantiate arbitrary objects if the application's environment contains classes with magic methods (such as __destruct(), __wakeup(), or __toString()) that perform dangerous actions when invoked.\nIn the context of Advanced Post Manager (versions n/a through 4.5.5), the plugin processes serialized data without implementing sufficient verification or using secure alternatives like JSON. When an attacker supplies a crafted serialized payload, the application deserializes the string, which forces the instantiation of objects defined in the codebase or included libraries.\nThe exploitation flow proceeds as follows: First, the attacker identifies an input vector within the plugin that processes serialized data. Second, the attacker constructs a malicious payload containing a serialized object structure designed to trigger specific methods upon destruction or wakeup. These methods are typically part of a 'gadget chain'—a sequence of existing code components that, when executed in a specific order, lead to unintended application states.\nIf the attacker successfully injects these objects, they can manipulate the execution flow of the application. For instance, if a gadget exists that facilitates file operations, the attacker might trigger arbitrary file reads or writes. If a chain exists that allows for method calls on arbitrary objects, the attacker could achieve Remote Code Execution by invoking system commands or loading malicious code files.\nThe vulnerability is particularly dangerous because it does not require complex interactions; the mere processing of the malicious payload by the vulnerable component is sufficient to trigger the exploit. The severity is contingent upon the availability of POP (Property-Oriented Programming) chains within the WordPress installation, including the plugin itself, other active plugins, or the WordPress core. As there is no inherent input validation or cryptographic signature verification on the serialized data, the plugin is unable to distinguish between legitimate data and attacker-injected payloads.\nGiven that this vulnerability affects the plugin's data processing logic, it is exposed to any user capable of interacting with the vulnerable entry point, potentially leading to complete site takeover, unauthorized administrative actions, or persistent backdoor installation."
}
CVE-2026-97283: Advanced Post Manager Object Injection (CRITICAL Severity, CVSS: 9.8) | Sceawere