What is CVE-2026-66620?
CVE-2026-66620 is a PHP Object Injection vulnerability in the Editor functionality of the OptionTree plugin, affecting versions up to 2.7.3. It allows authenticated users to inject malicious PHP objects, potentially leading to code execution; updating to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-66620, OptionTree plugininin 2.7.3 və daha əvvəlki versiyalarında Editor funksionallığı vasitəsilə PHP Object Injection zəifliyidir. Bu, təsdiqlənmiş istifadəçilərə təhlükəli PHP obyektləri inject edərək kod icrasına səbəb ola bilər; dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
In which functionality of the OptionTree plugin was the CVE-2026-66620 vulnerability discovered?
The CVE-2026-66620 vulnerability is a PHP Object Injection vulnerability discovered in the Editor functionality of the OptionTree plugin.
What level of access does an attacker need to exploit this vulnerability?
To exploit this vulnerability, the attacker must be an authenticated user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.