Skip to content
Threat Feed
high advisory

CVE-2026-87741: Deserialization Vulnerability in WordPress ConvertPlus Plugin

An authenticated deserialization vulnerability in ConvertPlus <= 3.6.3 allows subscribers to inject arbitrary PHP objects via the cp_display_preview_modal AJAX action.

CVE search metadata

CVE search record: CVE-2026-87741. Severity: high. CVSS: 8.8. KEV: no. Product: ConvertPlus (<= 3.6.3). Brief: CVE-2026-87741: Deserialization Vulnerability in WordPress ConvertPlus Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-09-convertplus-deserialization/

The ConvertPlus plugin for WordPress (versions 3.6.3 and earlier) is vulnerable to Deserialization of Untrusted Data. The vulnerability is triggered via the style parameter in the cp_display_preview_modal AJAX action. The flaw exists because the plugin fails to properly validate the cp_admin_page_nonce parameter; it defaults to a failed-open state when the parameter is omitted. Furthermore, the callback performs no capability checks and fails to strip shortcode delimiters from the style input. This allows a Subscriber-level user to inject a malicious [smile_modal] shortcode, which leads the smile_modal_popup function to pass attacker-supplied, base64-decoded data into the maybe_unserialize function without restricted class definitions. While ConvertPlus lacks its own POP chain, this vulnerability provides a critical vector for RCE or file manipulation if other installed themes or plugins contain exploitable POP chains.

Impact

Successful exploitation requires a WordPress user account with at least Subscriber-level access. The impact is dependent on the presence of secondary POP chains within the target environment. If a compatible chain is present, attackers may achieve arbitrary file deletion, sensitive data retrieval, or remote code execution. Given the prevalence of WordPress plugin ecosystems, this increases the attack surface for sites using common plugin combinations.

Recommendation

Prioritize updating the ConvertPlus plugin to the latest version. Monitor site-specific WordPress AJAX requests for signs of unauthorized access to the cp_display_preview_modal action.

  • Update the ConvertPlus plugin to the latest available version beyond 3.6.3.
  • Review installed plugins and themes to identify and remove software that contains known POP (Property Oriented Programming) chains.
  • Audit logs for unexpected AJAX requests to /wp-admin/admin-ajax.php involving the cp_display_preview_modal action.

Immediate actions

Upgrade ConvertPlus to latest version.

IT Operations 48h

Mitigations

Upgrade to version > 3.6.3

immediate IT Operations

CVE-2026-87741