Junglewise Threat Intelligence

CVE-2026-27053: VideoWhisper Broadcast Live Video PHP Object Injection

CVE-2026-27053 · Severity: critical · CVSS 9.8 · Published 2026-06-15

Executive brief

The Broadcast Live Video plugin for WordPress, which allows websites to stream live video content, contains a critical security flaw. An unauthorized attacker can remotely send malicious data to the plugin to take control of the website. This could lead to the theft of sensitive data, website defacement, or a total service outage.

Technical details

A PHP Object Injection vulnerability exists in the Broadcast Live Video plugin for WordPress due to the insecure deserialization of user-supplied input (CWE-502). The flaw allows an unauthenticated remote attacker to submit specially crafted input to the application. If the environment contains a suitable Property-Oriented Programming (POP) chain, the attacker can achieve remote code execution, perform SQL injection, or conduct path traversal. The vulnerability is resolved in version 7.1.3.

Affected products

  • VideoWhisper.com Broadcast Live Video < 7.1.3

Timeline

  • 2025-12-13: other: Vulnerability reported by researcher Phat RiO
  • 2026-05-28: advisory: Patchstack published advisory and mitigation rules
  • 2026-06-15: disclosed: CVE published to NVD

References