๐Ÿ” CVE Alert

CVE-2026-97188

UNKNOWN 0.0

String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed String locator WordPress plugin before 2.6.8 or , this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution.

Vendor unknown
Product string locator
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown string locator

Be the first to know when new unknown vulnerabilities affecting unknown string locator are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / String locator
0 < 2.6.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/cfb495ac-32fc-43e2-81b4-74faa8c164a4/

Credits

Raphael P. Cigana WPScan