Product
The PPWP WordPress plugin contains a PHP Object Injection vulnerability in the post_protection_roles parameter, allowing authenticated attackers to achieve remote code execution if a compatible POP chain exists in the environment.