Skip to main content
Vulnerability Database/CVE-2026-97188

CVE-2026-97188: String Locator WordPress Plugin RCE Vulnerability

CVE-2026-97188 is a deserialization flaw in String Locator WordPress plugin before 2.6.8 that enables unauthenticated attackers to achieve remote code execution. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-97188 Overview

CVE-2026-97188 is a PHP object injection vulnerability in the String locator WordPress plugin before version 2.6.8. The plugin does not restrict classes allowed during deserialization of database row content saved through its database editor. Unauthenticated attackers can store a serialized PHP object that is instantiated when an administrator later opens and saves the affected row. When a suitable Property-Oriented Programming (POP) chain exists in another installed plugin or theme, exploitation can lead to arbitrary file deletion, sensitive data disclosure, or remote code execution [CWE-502].

Critical Impact

Unauthenticated attackers can plant malicious serialized payloads that execute arbitrary code once an administrator interacts with the affected database row.

Affected Products

  • String locator WordPress plugin versions prior to 2.6.8
  • WordPress installations with the plugin's database editor enabled
  • Sites where additional plugins or themes expose exploitable POP chains

Discovery Timeline

  • 2026-10-07 - CVE-2026-97188 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-97188

Vulnerability Analysis

The String locator plugin provides an administrative database editor that reads and writes raw database row content. When a row is loaded and saved, the plugin passes stored content through PHP's unserialize() function without filtering the allowed classes. Any serialized object placed in the targeted row is instantiated during this operation.

Because the plugin does not restrict allowed classes, attackers can inject arbitrary object types. Instantiation triggers PHP magic methods such as __wakeup(), __destruct(), or __toString(). These methods, when chained through gadget code from other installed plugins or themes, form a POP chain that attackers use to reach dangerous sinks like file_put_contents(), unlink(), or eval().

Root Cause

The root cause is unsafe deserialization of attacker-controllable data stored in database rows. The plugin invokes unserialize() on content without specifying the allowed_classes option introduced in PHP 7. This permits instantiation of any class loaded into the WordPress runtime, including gadget classes from third-party extensions.

Attack Vector

Exploitation requires two steps. First, an unauthenticated attacker writes a serialized PHP object into a database row reachable through the plugin's editor. Second, an administrator opens and saves that row, triggering deserialization. The attack requires user interaction (UI:R) from a privileged account but no attacker authentication. Successful exploitation depends on the presence of a usable POP chain elsewhere on the site.

See the WPScan Vulnerability Report for additional technical details.

Detection Methods for CVE-2026-97188

Indicators of Compromise

  • Database rows containing PHP serialized object strings matching patterns such as O:<length>:"<ClassName>":
  • Unexpected files created, modified, or deleted within WordPress directories after an administrator edits a database row
  • New PHP files appearing in wp-content/uploads/ or theme directories
  • Outbound network connections initiated by the PHP-FPM or Apache worker handling admin requests

Detection Strategies

  • Scan the WordPress database for serialized object payloads in tables writable through the String locator editor
  • Monitor web server logs for unauthenticated POST requests targeting database endpoints writable by the plugin
  • Alert on administrator sessions immediately followed by file system writes to executable PHP paths

Monitoring Recommendations

  • Enable file integrity monitoring across wp-content/ to flag unauthorized changes
  • Log and review calls to unserialize() through PHP error reporting or an application firewall
  • Track plugin version inventory to confirm all WordPress sites run String locator 2.6.8 or later

How to Mitigate CVE-2026-97188

Immediate Actions Required

  • Upgrade the String locator plugin to version 2.6.8 or later on every WordPress installation
  • Audit database tables accessible through the plugin editor for serialized object strings and remove suspicious entries
  • Rotate administrator credentials and session tokens if exploitation is suspected

Patch Information

The maintainer addressed the vulnerability in String locator version 2.6.8 by restricting classes allowed during deserialization. Administrators should install the update through the WordPress plugin interface or by replacing plugin files directly. Confirm the installed version by inspecting the plugin header after the upgrade.

Workarounds

  • Deactivate the String locator plugin until the patched version can be deployed
  • Restrict administrator access to the WordPress dashboard using IP allowlists or VPN enforcement
  • Remove unused plugins and themes to reduce the pool of classes available for POP chain construction
bash
# Verify installed String locator version via WP-CLI
wp plugin get string-locator --field=version

# Update to the patched release
wp plugin update string-locator --version=2.6.8

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.