Junglewise Threat Intelligence

CVE-2026-39478: Eli Scheetz Anti-Malware Security and Brute-Force Firewall PHP Object Injection

CVE-2026-39478 · Severity: high · CVSS 8.8 · Published 2026-06-15

Executive brief

A security vulnerability exists in the Anti-Malware Security and Brute-Force Firewall plugin for WordPress, which is designed to protect websites from malicious attacks. An attacker with basic contributor-level access can exploit this flaw to potentially take full control of the website, steal sensitive data, or cause a complete service outage. This is particularly serious as the plugin is intended to be a security defense, but could instead be used as a foothold for further attacks.

Technical details

A PHP Object Injection vulnerability (CWE-502) exists in the Anti-Malware Security and Brute-Force Firewall plugin for WordPress due to the unsafe deserialization of user-supplied input. An attacker with 'Contributor' level privileges or higher can submit specially crafted input that, when processed by the plugin, allows for the injection of arbitrary PHP objects. If a suitable Property-Oriented Programming (POP) chain is present on the system, this can lead to remote code execution (RCE), SQL injection, or unauthorized file access. The vulnerability is patched in version 4.23.88.

Affected products

  • Eli Scheetz Anti-Malware Security and Brute-Force Firewall <= 4.23.87

Timeline

  • 2026-02-25: other: Reported by researcher daroo
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-04-20: patched: Version 4.23.88 released
  • 2026-06-15: disclosed: NVD publication date

References

Related threats