What is CVE-2026-10035?
CVE-2026-10035 is a PHP Object Injection vulnerability in the Turnkey bbPress by WeaverTheme plugin for WordPress, affecting versions up to and including 1.7.1. It allows remote code execution through deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function. Update the plugin to the latest patched version immediately.
Azərbaycanca: CVE-2026-10035, WeaverTheme şirkətinin WordPress üçün hazırladığı "Turnkey bbPress" plaginində aşkar edilmiş PHP Object Injection zəifliyidir. 1.7.1 daxil olmaqla bütün versiyalar təsirlənir və wvrbbp_set_to_serialized_values() funksiyasındakı deserialization problemi səbəbindən uzaqdan kod icrasına imkan yarada bilər. Təsirlənmiş plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which function in the Turnkey bbPress plugin is associated with the CVE-2026-10035 vulnerability?
The issue arises from the deserialization in the wvrbbp_set_to_serialized_values() function.
What action is recommended to mitigate the CVE-2026-10035 vulnerability?
Update the affected plugin to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.