ZeroBreach Request early access
← All security news
critical CVE-2026-97283

Critical PHP object injection in Advanced Post Manager (CVE-2026-97283)

Tags: wordpress, plugin, object-injection

Advanced Post Manager versions ≤ 4.5.5 are affected by a critical PHP object injection vulnerability (CVE-2026-97283, CVSS 9.8). Object injection flaws at this severity can frequently be chained into full site takeover.

What to do

  • Update to 4.5.6 or later immediately.
  • Audit for signs of exploitation: unexpected admin users, unfamiliar files in wp-content, and anomalous entries in access logs around the disclosure date.
  • If the plugin is not essential to the site, consider removing it entirely. fewer plugins means fewer targets.

A CVSS 9.8 in a plugin you may have installed years ago and forgotten is the norm, not the exception. ZeroBreach’s application-layer audit exists so nothing on your server stays forgotten.