Junglewise Threat Intelligence

CVE-2026-4703: WS Form LITE PHP Object Injection in form submission

CVE-2026-4703 · Severity: critical · CVSS 9.8 · Published 2026-08-22

Executive brief

WS Form LITE is a WordPress plugin used to build contact forms and collect user submissions. The plugin deserializes untrusted data from form submissions without validation, allowing attackers to inject malicious PHP objects. While the plugin itself contains no exploitable code path, if other vulnerable plugins or themes are installed, attackers could leverage them to delete files, steal data, or execute arbitrary code on the server.

Technical details

The vulnerability is a PHP Object Injection (deserialization) flaw in form submission meta value handling across all versions up to 1.10.80. Unauthenticated attackers can inject arbitrary serialized PHP objects through form fields, which are then unserialized without proper validation. The attack requires no authentication and is network-accessible via form submission. The vulnerability has no direct impact in isolation, but becomes critical if a Property-Oriented Programming (POP) chain exists in another installed plugin or theme, potentially allowing arbitrary file deletion, information disclosure, or remote code execution.

Affected products

  • WS Form WS Form LITE up to 1.10.80

Timeline

  • 2026-08-22: disclosed

References

Related threats