{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kalles-addons/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-78572"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kalles Addons"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Kalles Addons plugin for WordPress, in versions up to and including 1.0.6, contains a critical vulnerability involving the insecure deserialization of untrusted input. An unauthenticated attacker can supply a serialized PHP object to specific input vectors processed by the plugin, leading to PHP Object Injection. While the plugin itself lacks an embedded Property Oriented Programming (POP) chain, the vulnerability is highly significant for environments that host multiple plugins or themes. If a secondary, vulnerable, or complex component is present on the same WordPress instance, an attacker can leverage its existing POP chain to achieve arbitrary file deletion, data exfiltration, or remote code execution. Because this vulnerability originates from the plugin's handling of user-supplied data, detection must focus on identifying suspicious input patterns in web server logs.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation depends on the existence of a POP chain within the target WordPress site's plugin or theme ecosystem. If such a chain is identified, the attacker can achieve remote code execution (RCE) or escalate privileges to perform unauthorized actions such as deleting sensitive site configuration files or stealing database contents, potentially leading to a full site compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit all WordPress installations to identify and update the Kalles Addons plugin to a version beyond 1.0.6 or remove the plugin if updates are unavailable.\u003c/li\u003e\n\u003cli\u003ePerform a comprehensive review of all installed themes and plugins to identify potential POP chain gadgets that could be leveraged by this vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation at the web application firewall (WAF) level to block requests containing serialized PHP objects directed at the vulnerable endpoints.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests containing PHP serialization markers (e.g., O:[0-9]+:).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-25T12:08:09Z","date_published":"2026-08-25T12:08:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-78572/","summary":"The Kalles Addons plugin for WordPress (\u003c= 1.0.6) is vulnerable to unauthenticated PHP Object Injection, which may allow remote code execution or file operations if a compatible POP chain exists in the environment.","title":"PHP Object Injection in Kalles Addons for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-78572/"}],"language":"en","title":"CraftedSignal Threat Feed - Kalles Addons","version":"https://jsonfeed.org/version/1.1"}