Junglewise Threat Intelligence

CVE-2026-0677: TotalSuite TotalContest Lite PHP object injection

CVE-2026-0677 · Severity: medium · CVSS 6.3 · Published 2026-03-20

Executive brief

TotalContest Lite is a WordPress plugin used to create and manage online contests and polls. A security flaw allows an attacker with basic user permissions to inject malicious data that the website then processes incorrectly. If successful, this could allow the attacker to interfere with site operations, access sensitive information, or potentially take control of the website depending on the server configuration.

Technical details

A PHP Object Injection vulnerability exists in TotalSuite TotalContest Lite (versions <= 2.9.1) due to the deserialization of untrusted data (CWE-502). The vulnerability allows an authenticated attacker, typically with 'Author' level privileges or higher, to inject a specially crafted PHP object via a network request. If a suitable Property-Oriented Programming (POP) chain is present in the application or other installed plugins, this can lead to remote code execution, file manipulation, or unauthorized database access. As of the latest advisory, no official patch has been confirmed, and users are advised to monitor for updates from the vendor.

Affected products

  • TotalSuite TotalContest Lite <= 2.9.1

Timeline

  • 2025-12-09: other: Vulnerability reported by researcher hhhai
  • 2026-03-10: disclosed: Initial disclosure by Patchstack
  • 2026-03-20: advisory: CVE published to NVD

References