What is CVE-2026-73389?
This vulnerability allows unauthenticated PHP Object Injection in Kalles Addons plugin versions <= 1.0.6. It's critical to update the plugin to the latest version immediately.
Azərbaycanca: Bu zəiflik Kalles Addons plagininin 1.0.6 və daha əvvəl versiyalarında autentifikasiya olunmamış PHP obyekt inyeksiyasına imkan verir. Təcili olaraq plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which versions of the Kalles Addons plugin are affected by CVE-2026-73389?
This vulnerability exists in Kalles Addons plugin versions 1.0.6 and earlier.
What should be done to protect against CVE-2026-73389?
It is critical to update the Kalles Addons plugin to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.