CVE-2026-65556
MihChe · WPBruiser {no- Captcha anti-Spam}
The WPBruiser {no- Captcha anti-Spam} WordPress plugin is vulnerable to unauthenticated PHP object injection, enabling attackers to execute arbitrary code via the deserialization of untrusted data.
Executive summary
A critical PHP object injection vulnerability in the WPBruiser {no- Captcha anti-Spam} plugin allows unauthenticated attackers to gain remote code execution and compromise the host environment.
Vulnerability
The plugin fails to properly validate input during deserialization (CWE-502). An unauthenticated attacker can leverage this flaw to inject malicious objects, which can trigger arbitrary code execution within the context of the WordPress installation.
Business impact
Successful exploitation allows an attacker to seize control of the web application, leading to complete data exfiltration, modification of site content, or the installation of persistent backdoors. Given the 9.8 CVSS score, the impact on confidentiality, integrity, and availability is total, creating a significant risk to organizational data security and service continuity.
Remediation
Immediate Action: Update the WPBruiser {no- Captcha anti-Spam} plugin to the latest available version if a patch has been issued, or deactivate the plugin immediately if no update is currently available.
Proactive Monitoring: Monitor application logs for anomalous requests, particularly those containing serialized PHP objects, which may indicate an attempt to exploit this vulnerability.
Compensating Controls: Use a Web Application Firewall (WAF) to filter incoming traffic and block requests containing suspicious serialized data patterns.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is highly critical and presents an immediate threat to the security of affected WordPress sites. Administrators should take swift action to update the plugin or remove it from the production environment to eliminate the risk of total system compromise.