| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. |
| Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions. |
| Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. |
| Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. |
| Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. |
| Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. |
| Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. |
| Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. |
| Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. |
| Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. |
| Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. |
| Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. |
| Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. |
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. |
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. |
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. |
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. |
| The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or . |
| A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards.
This vulnerability was patched on 28 June 2026, and no customer action is needed. |
| The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.
The created account receives the site's default role. |