Description
Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.
Published: 2026-10-05
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution via PHP Object Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a Deserialization of Untrusted Data flaw that permits PHP Object Injection. By injecting crafted serialized objects into the plugin’s processing flow, an attacker can write arbitrary code to the server, potentially taking full control of the application. The weakness is identified as CWE‑502, which highlights the risks of improper handling of serialized data.

Affected Systems

The defect exists in the WordPress WP Spell Check plugin, affecting all versions from the initial release up to and including 12.1. No specific sub‑version list is provided, but the issue applies to every iteration before version 12.2.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. Although the EPSS score is not available, the absence of a listing in the CISA KEV catalog suggests no known large‑scale exploitation yet, but the potential for remote code execution remains. The attack likely requires sending specially crafted serialized data to a plugin endpoint that processes user input. Based on the description, it is inferred that the plugin accepts untrusted data via standard HTTP requests, making remote exploitation possible.

Generated by OpenCVE AI on October 5, 2026 at 20:23 UTC.

Remediation

Vendor Solution

Update the WordPress WP Spell Check plugin to the latest available version (at least 12.2).


OpenCVE Recommended Actions

  • Apply the latest patch and upgrade the WP Spell Check plugin to version 12.2 or later.
  • Deploy a web application firewall rule that detects and blocks serialized PHP objects or signatures commonly used for object injection attempts.
  • If the plugin is not essential, consider disabling or removing it to eliminate the attack surface.

Generated by OpenCVE AI on October 5, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.
Title WordPress WP Spell Check plugin <= 12.1 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T19:00:11.321Z

Reserved: 2026-09-26T00:17:50.215Z

Link: CVE-2026-100506

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T20:17:03.760

Modified: 2026-10-05T20:17:03.760

Link: CVE-2026-100506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:30:22Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data