Executive brief
The Paid Videochat Turnkey Site plugin for WordPress, which provides live webcam and pay-per-view video services, contains a critical security flaw. An unauthorized attacker can exploit this vulnerability to potentially take control of the website, access the administrative panel, or disrupt services. This type of flaw is often targeted in automated mass-exploitation campaigns against websites.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in the VideoWhisper Paid Videochat Turnkey Site plugin for WordPress in versions up to and including 7.3.23. The flaw allows an unauthenticated remote attacker to submit malicious serialized data to the application. If the application processes this data using vulnerable 'gadget chains' within the environment, the attacker could achieve arbitrary code execution, bypass security logic, or gain unauthorized access to the WordPress administrative dashboard. The vulnerability is addressed in version 7.3.24.
Affected products
- VideoWhisper.com Paid Videochat Turnkey Site (ppv-live-webcams) <= 7.3.23
Timeline
- 2025-12-04: other: Reported by Phat RiO
- 2026-05-28: advisory: Initial advisory published by Patchstack
- 2026-06-15: disclosed: CVE published to NVD
- 2026-05-28: patched: Version 7.3.24 released to address the vulnerability