CVE-2026-97188 PUBLISHED

String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor

Assigner: WPScan
Reserved: 24.09.2026 Published: 07.10.2026 Updated: 07.10.2026

The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed String locator WordPress plugin before 2.6.8 or , this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution.

Product Status

Vendor Unknown
Product String locator
Versions Default: unaffected
  • affected from 0 to 2.6.8 (excl.)

Credits

  • Raphael P. Cigana finder
  • WPScan coordinator

References

Problem Types

  • CWE-502 Deserialization of Untrusted Data CWE