Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82925— Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature

Quick assessment

Affected
Unknown Site Reviews
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Site Reviews WordPress 插件在 8.3.0 版本之前未对请求数据中的反序列化操作进行防护,并通过填充(padding)该站点的 WordPress 非空值密钥(nonce key)来推导用于保护这些数据的密钥。在那些密钥缺失、仍为默认示例值或过短而缺乏保密性的安装环境中,该密钥可被公开计算得出。这使得未认证用户能够在此类环境中注入任意 PHP 对象。由于 Site Reviews 插件 8.3.0 之前的自身代码中不存在从注入对象出发的后续利用链,因此漏洞的影响范围取决于站点上其他代码的具体情

AI Predicted 9.8 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82925

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature
Source: CVE Program / CVE List V5
Vulnerability Description
The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such installs. The Site Reviews WordPress plugin before 8.3.0's own code contains no chain onward from the injected object, so how far it reaches depends on the other code present on the site.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Site Reviews 7.2.2 ~ 8.3.0 -

II. Public POCs for CVE-2026-82925

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82925

登录查看更多情报信息。

Proof of Concept for CVE-2026-82925 (1)

Same Patch Batch · Unknown · 2026-09-10 · 8 CVEs total

CVE-2026-81431 Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Un
CVE-2026-77770 miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Em
CVE-2026-77771 miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout
CVE-2026-78361 zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Optio
CVE-2026-19840 Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions
CVE-2026-19436 Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v
CVE-2026-19439 Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Cus

IV. Related Vulnerabilities

V. Comments for CVE-2026-82925

No comments yet


Leave a comment