Description
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
Published: 2026-09-30
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution via PHP Object Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a PHP Object Injection flaw affecting the Page Builder by SiteOrigin plugin for WordPress versions up to 2.36.0. An attacker who can supply crafted input to the editor can cause the plugin to unserialize untrusted data, leading to execution of arbitrary PHP code on the server. This grants full control over the affected WordPress site, allowing the attacker to modify content, install additional malware, or compromise the underlying server.

Affected Systems

The affected product is Greg – SiteOrigin Page Builder by SiteOrigin, a popular WordPress plugin used to design pages via a drag‑and‑drop interface. Any WordPress installation running a plugin version 2.36.0 or earlier is impacted. Versions 2.36.1 and later contain the patch.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity level. No EPSS score is available, so the current exploitation probability is unknown but the lack of public exploitation reports should not reduce the urgency. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to target sites with the vulnerable plugin by sending malicious requests to the editor endpoint, exploiting the unserialize call to inject malicious objects. No authentication requirement is explicitly stated, so the risk could affect both authenticated and unauthenticated users, but the exact prerequisites are not detailed.

Generated by OpenCVE AI on September 30, 2026 at 19:53 UTC.

Remediation

Vendor Solution

Update the WordPress Page Builder by SiteOrigin plugin to the latest available version (at least 2.36.1).


OpenCVE Recommended Actions

  • Update the Page Builder by SiteOrigin plugin to version 2.36.1 or later.
  • If the plugin cannot be updated immediately, disable or remove it from the WordPress installation to prevent use by attackers.
  • Keep WordPress core and all other plugins up to date to reduce the window for exploitation and to patch related code paths.

Generated by OpenCVE AI on September 30, 2026 at 19:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Greg–siteorigin
Greg–siteorigin page Builder By Siteorigin
Wordpress-extensions
Wordpress-extensions page Builder By Siteorigin
Vendors & Products Greg–siteorigin
Greg–siteorigin page Builder By Siteorigin
Wordpress-extensions
Wordpress-extensions page Builder By Siteorigin

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
Title WordPress Page Builder by SiteOrigin plugin <= 2.36.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Greg–siteorigin Page Builder By Siteorigin
Wordpress-extensions Page Builder By Siteorigin
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T17:59:56.028Z

Reserved: 2026-09-24T10:23:10.131Z

Link: CVE-2026-97256

cve-icon Vulnrichment

Updated: 2026-09-30T17:59:28.540Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:18:44.240

Modified: 2026-09-30T19:04:41.917

Link: CVE-2026-97256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:35:57Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data