Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97188— String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor

Quick assessment

Affected
Unknown String locator
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress String Locator 插件在 2.6.8 版本之前存在一个反序列化漏洞。该漏洞源于插件在反序列化通过其数据库编辑器保存的数据库行内容时,未对允许的类进行限制。攻击者无需身份验证即可存储一个已序列化的 PHP 对象,当管理员后续打开并保存该行时,该对象会被实例化。如果系统中已安装的其他 String Locator WordPress 插件(版本低于 2.6.8)中存在合适的 POP(面向属性的编程)链,则可能导致任意文件删除、敏感数据泄露或远程代码执行。

AI Predicted 9.8 Difficulty: Moderate EPSS 0.38% · P29

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown String locator < 2.6.8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97188

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor
Source: CVE Program / CVE List V5
Vulnerability Description
The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed String locator WordPress plugin before 2.6.8 or , this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown String locator 0 ~ 2.6.8 -

II. Public POCs for CVE-2026-97188

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97188

请登录查看更多情报信息。

Other References for CVE-2026-97188 (1)

Same Patch Batch · Unknown · 2026-10-07 · 24 CVEs total

CVE-2026-82211 8.2 HIGH Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure
CVE-2026-82212 7.5 HIGH Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler
CVE-2026-86833 5.4 MEDIUM MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcod
CVE-2026-105322 5.3 MEDIUM Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form
CVE-2026-103323 Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler
CVE-2026-104049 Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpo
CVE-2026-104651 Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulat
CVE-2026-104652 Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID
CVE-2026-104050 Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answ
CVE-2026-103681 Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_prof
CVE-2026-103378 Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Publ
CVE-2026-104653 Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions
CVE-2026-104953 MPG < 4.2.3 - Editor+ SQLi via Project Import
CVE-2026-104677 WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP
CVE-2026-104667 Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order
CVE-2026-104678 CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update
CVE-2026-105316 Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Acti
CVE-2026-86816 WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API
CVE-2026-87971 If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter
CVE-2026-87782 Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator

Showing top 20 of 24 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97188

No comments yet


Leave a comment