Junglewise Threat Intelligence

CVE-2026-82925: WordPress Site Reviews PHP object injection via form signature

CVE-2026-82925 · Severity: high · CVSS 8.1 · Published 2026-09-10

Vendors: Automattic.

Executive brief

The Site Reviews WordPress plugin contains a vulnerability that allows unauthenticated attackers to inject arbitrary PHP objects into affected websites. The plugin fails to properly secure its form signature mechanism, making it possible to forge valid requests on sites with weak or default WordPress configuration keys. Depending on what other plugins or code are installed on the site, a successful attack could lead to arbitrary code execution, data theft, or complete site compromise.

Technical details

The vulnerability is a PHP object injection (deserialization) issue in the Site Reviews plugin versions 7.2.2 through 8.2.2, classified as CWE-502 (Insecure Deserialization). The plugin deserializes untrusted request data without validation and protects it using a key derived from the site's WordPress nonce key with padding. On installations where the nonce key is absent, set to its sample value, or too short, this derived key becomes publicly computable, allowing unauthenticated attackers to craft malicious serialized PHP objects. While the plugin's own code contains no gadget chains to exploit the injected objects, attackers can achieve remote code execution if suitable gadget chains exist in other installed plugins or WordPress core components.

Affected products

  • Automattic Site Reviews 7.2.2 to 8.2.2

Timeline

  • 2026-09-08: disclosed
  • 2026-09-10: patched: Fixed in version 8.3.0

References