๐Ÿ” CVE Alert

CVE-2026-14602

UNKNOWN 0.0

Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.

Vendor unknown
Product remote api
Published Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown remote api

Be the first to know when new unknown vulnerabilities affecting unknown remote api are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Remote API
0 โ‰ค 0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/eb5a7d86-4762-48ad-83bf-81f048527147/

Credits

Pedro Pinho WPScan