What is CVE-2026-32470?
CVE-2026-32470 allows unauthenticated PHP Object Injection in FundEngine plugin versions 1.7.9 and below, potentially leading to remote code execution. Users should immediately update to the latest version.
Azərbaycanca: CVE-2026-32470, FundEngine plaginin 1.7.9 və daha əvvəlki versiyalarında autentifikasiya olunmadan PHP Object Injection zəifliyinə yol açır. Bu, uzaqdan kod icrasına səbəb ola bilər. İstifadəçilər dərhal əlavəni ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which versions of the FundEngine plugin are affected by CVE-2026-32470?
This vulnerability affects FundEngine plugin versions 1.7.9 and below.
What type of threat can arise if CVE-2026-32470 is exploited?
Exploitation can lead to Remote Code Execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.