oM noM Security Feeds cve
vulnerability context

CVE-2026-7654

CVSS 8.8 HIGHEPSS 65%CWE-502OTX 4 pulses

The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()` function, which processes attacker-controlled post meta values without proper validation. This makes it possible for authenticated attackers with Contributor-level access and above to inject a serialized PHP object into a post's custom meta field and trigger arbitrary code execution by exploiting a bundled POP gadget ...

Published 2026-06-05 · last modified 2026-06-08

details

CISA KEV status
Not in catalog
CVSS v3
8.8 / HIGH
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
65% percentile (score 0.0047)
CWE
CWE-502
OTX pulses
4 total, 0 recent

source mentions 2

source consensus

  • Bluesky
Want the 3-bullet summary of CVE-2026-7654, plus webhook alerts when KEV is updated? Pro is $10/mo.