Description
Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Deserialization of untrusted data in the bPlugins Super Video Player plugin can lead to PHP object injection. An attacker who can supply crafted serialized data may be able to create or manipulate objects, potentially allowing execution of arbitrary PHP code on the WordPress site. The vulnerability directly compromises the integrity and confidentiality of the application and could lead to full system compromise.

Affected Systems

The vulnerability affects the bPlugins Super Video Player WordPress plugin for all releases from the initial version through 1.8.13. Any WordPress installation using this plugin within that version range is impacted.

Risk and Exploitability

The CVSS score of 7.2 indicates a high level of risk. EPSS information is not available, and the vulnerability is not listed in CISA KEV, so no publicly known exploit data is present. Based on the description, the likely attack vector involves an attacker supplying a malicious serialized payload to the plugin via an input field or URL parameter that is later deserialized without validation. This exploitation path requires the attacker to have access to the WordPress site’s file system or to supply input through form fields that are processed by the plugin, suggesting that the threat could be realized in a web‑based context if the plugin accepts external data.

Generated by OpenCVE AI on October 10, 2026 at 18:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Super Video Player plugin to a version newer than 1.8.13.
  • If upgrading is not immediately possible, disable or remove the Super Video Player plugin from the WordPress installation to eliminate the attack surface.
  • Implement monitoring for abnormal PHP activity or attempts to execute serialized data, and review server logs for unexpected changes to application objects.

Generated by OpenCVE AI on October 10, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.
Title WordPress Super Video Player plugin <= 1.8.13 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T17:00:09.638Z

Reserved: 2026-07-13T06:14:38.874Z

Link: CVE-2026-62044

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T17:17:00.803

Modified: 2026-10-10T17:17:00.803

Link: CVE-2026-62044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T18:30:08Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data