Critical PHP object injection in Advanced Post Manager (CVE-2026-97283)
Advanced Post Manager versions ≤ 4.5.5 are affected by a critical PHP object injection vulnerability (CVE-2026-97283, CVSS 9.8). Object injection flaws at this severity can frequently be chained into full site takeover.
What to do
- Update to 4.5.6 or later immediately.
- Audit for signs of exploitation: unexpected admin users, unfamiliar files in
wp-content, and anomalous entries in access logs around the disclosure date. - If the plugin is not essential to the site, consider removing it entirely. fewer plugins means fewer targets.
A CVSS 9.8 in a plugin you may have installed years ago and forgotten is the norm, not the exception. ZeroBreach’s application-layer audit exists so nothing on your server stays forgotten.