<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Brainstorm Force - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/brainstorm-force/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 20:21:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/brainstorm-force/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-87741: Deserialization Vulnerability in WordPress ConvertPlus Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-convertplus-deserialization/</link><pubDate>Mon, 28 Sep 2026 20:21:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-convertplus-deserialization/</guid><description>An authenticated deserialization vulnerability in ConvertPlus &lt;= 3.6.3 allows subscribers to inject arbitrary PHP objects via the cp_display_preview_modal AJAX action.</description><content:encoded><![CDATA[<p>The ConvertPlus plugin for WordPress (versions 3.6.3 and earlier) is vulnerable to Deserialization of Untrusted Data. The vulnerability is triggered via the style parameter in the cp_display_preview_modal AJAX action. The flaw exists because the plugin fails to properly validate the cp_admin_page_nonce parameter; it defaults to a failed-open state when the parameter is omitted. Furthermore, the callback performs no capability checks and fails to strip shortcode delimiters from the style input. This allows a Subscriber-level user to inject a malicious [smile_modal] shortcode, which leads the smile_modal_popup function to pass attacker-supplied, base64-decoded data into the maybe_unserialize function without restricted class definitions. While ConvertPlus lacks its own POP chain, this vulnerability provides a critical vector for RCE or file manipulation if other installed themes or plugins contain exploitable POP chains.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation requires a WordPress user account with at least Subscriber-level access. The impact is dependent on the presence of secondary POP chains within the target environment. If a compatible chain is present, attackers may achieve arbitrary file deletion, sensitive data retrieval, or remote code execution. Given the prevalence of WordPress plugin ecosystems, this increases the attack surface for sites using common plugin combinations.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize updating the ConvertPlus plugin to the latest version. Monitor site-specific WordPress AJAX requests for signs of unauthorized access to the cp_display_preview_modal action.</p>
<ul>
<li>Update the ConvertPlus plugin to the latest available version beyond 3.6.3.</li>
<li>Review installed plugins and themes to identify and remove software that contains known POP (Property Oriented Programming) chains.</li>
<li>Audit logs for unexpected AJAX requests to /wp-admin/admin-ajax.php involving the cp_display_preview_modal action.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>deserialization</category><category>web-vulnerability</category></item></channel></rss>