CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,987 vulnerabilities with CWE-502
CVE-2026-54806 CRITICAL
WordPress WP Activity Log plugin <= 5.6.3.1 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-54194 CRITICAL
WordPress Fusion Builder plugin <= 3.15.4 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-52706 CRITICAL
WordPress JetEngine plugin <= 3.8.10 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49107 CRITICAL
WordPress Thrive Apprentice plugin < 10.8.10.2 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-49075 CRITICAL
WordPress JetEngine plugin <= 3.8.9.1 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-42380 CRITICAL
WordPress AI Lab theme < 5.4.2 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-40761 HIGH
WordPress Valeska theme <= 1.2.2 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40760 HIGH
WordPress Behold theme <= 1.5 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40759 HIGH
WordPress Esmée theme <= 1.4 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40758 HIGH
WordPress Léonie theme <= 1.2.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40755 HIGH
WordPress TechLink theme <= 1.3 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40754 HIGH
WordPress Roisin theme <= 1.4 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40753 HIGH
WordPress EasyMeals theme <= 1.5.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40751 HIGH
WordPress Ashtanga theme <= 1.2 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40739 HIGH
WordPress LuxeDrive theme <= 1.4 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40736 HIGH
WordPress Laurits theme <= 1.5.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40735 HIGH
WordPress Reina theme <= 2.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-40725 CRITICAL
WordPress WooCommerce Product Filters plugin < 2.0.6 - PHP Object Injection vulnerability
CVSS 9.8
CVE-2026-39580 HIGH
WordPress Micdrop theme <= 1.3.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39578 MEDIUM
WordPress Valiance theme <= 1.2 - PHP Object Injection vulnerability
CVSS 5.5
CVE-2026-39577 MEDIUM
WordPress Playroom theme <= 1.4.1 - PHP Object Injection vulnerability
CVSS 5.5
CVE-2026-39573 HIGH
WordPress Mildhill theme <= 1.5 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39567 HIGH
WordPress Santé theme <= 1.5.1 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39557 HIGH
WordPress NeoBeat theme <= 1.7 - PHP Object Injection vulnerability
CVSS 8.1
CVE-2026-39554 HIGH
WordPress Fidalgo theme <= 1.2.2 - PHP Object Injection vulnerability
CVSS 8.1
Details
Vulnerabilities 2,987
Exploit Likelihood Medium