CVE-2026-97188 Overview
CVE-2026-97188 is a PHP object injection vulnerability in the String locator WordPress plugin before version 2.6.8. The plugin does not restrict classes allowed during deserialization of database row content saved through its database editor. Unauthenticated attackers can store a serialized PHP object that is instantiated when an administrator later opens and saves the affected row. When a suitable Property-Oriented Programming (POP) chain exists in another installed plugin or theme, exploitation can lead to arbitrary file deletion, sensitive data disclosure, or remote code execution [CWE-502].
Critical Impact
Unauthenticated attackers can plant malicious serialized payloads that execute arbitrary code once an administrator interacts with the affected database row.
Affected Products
- String locator WordPress plugin versions prior to 2.6.8
- WordPress installations with the plugin's database editor enabled
- Sites where additional plugins or themes expose exploitable POP chains
Discovery Timeline
- 2026-10-07 - CVE-2026-97188 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-97188
Vulnerability Analysis
The String locator plugin provides an administrative database editor that reads and writes raw database row content. When a row is loaded and saved, the plugin passes stored content through PHP's unserialize() function without filtering the allowed classes. Any serialized object placed in the targeted row is instantiated during this operation.
Because the plugin does not restrict allowed classes, attackers can inject arbitrary object types. Instantiation triggers PHP magic methods such as __wakeup(), __destruct(), or __toString(). These methods, when chained through gadget code from other installed plugins or themes, form a POP chain that attackers use to reach dangerous sinks like file_put_contents(), unlink(), or eval().
Root Cause
The root cause is unsafe deserialization of attacker-controllable data stored in database rows. The plugin invokes unserialize() on content without specifying the allowed_classes option introduced in PHP 7. This permits instantiation of any class loaded into the WordPress runtime, including gadget classes from third-party extensions.
Attack Vector
Exploitation requires two steps. First, an unauthenticated attacker writes a serialized PHP object into a database row reachable through the plugin's editor. Second, an administrator opens and saves that row, triggering deserialization. The attack requires user interaction (UI:R) from a privileged account but no attacker authentication. Successful exploitation depends on the presence of a usable POP chain elsewhere on the site.
See the WPScan Vulnerability Report for additional technical details.
Detection Methods for CVE-2026-97188
Indicators of Compromise
- Database rows containing PHP serialized object strings matching patterns such as O:<length>:"<ClassName>":
- Unexpected files created, modified, or deleted within WordPress directories after an administrator edits a database row
- New PHP files appearing in wp-content/uploads/ or theme directories
- Outbound network connections initiated by the PHP-FPM or Apache worker handling admin requests
Detection Strategies
- Scan the WordPress database for serialized object payloads in tables writable through the String locator editor
- Monitor web server logs for unauthenticated POST requests targeting database endpoints writable by the plugin
- Alert on administrator sessions immediately followed by file system writes to executable PHP paths
Monitoring Recommendations
- Enable file integrity monitoring across wp-content/ to flag unauthorized changes
- Log and review calls to unserialize() through PHP error reporting or an application firewall
- Track plugin version inventory to confirm all WordPress sites run String locator 2.6.8 or later
How to Mitigate CVE-2026-97188
Immediate Actions Required
- Upgrade the String locator plugin to version 2.6.8 or later on every WordPress installation
- Audit database tables accessible through the plugin editor for serialized object strings and remove suspicious entries
- Rotate administrator credentials and session tokens if exploitation is suspected
Patch Information
The maintainer addressed the vulnerability in String locator version 2.6.8 by restricting classes allowed during deserialization. Administrators should install the update through the WordPress plugin interface or by replacing plugin files directly. Confirm the installed version by inspecting the plugin header after the upgrade.
Workarounds
- Deactivate the String locator plugin until the patched version can be deployed
- Restrict administrator access to the WordPress dashboard using IP allowlists or VPN enforcement
- Remove unused plugins and themes to reduce the pool of classes available for POP chain construction
# Verify installed String locator version via WP-CLI
wp plugin get string-locator --field=version
# Update to the patched release
wp plugin update string-locator --version=2.6.8
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.