What the vulnerability does
01Description
The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. An administrator must perform a search and replace action to trigger the exploit.
Explanation of Vulnerability in Simple Terms
02Summary
InstaWP String Locator versions 2.6.6 and earlier contain a deserialization vulnerability that allows attackers to execute arbitrary code on affected sites. An attacker can craft a malicious serialized object that, when deserialized by the plugin, executes code with the privileges of the web server. User interaction is required—the victim must visit a specially crafted page or click a malicious link.
What an attacker can do
03Attacker Capabilities
Run arbitrary code on the site with web server privileges.
Potential impact on your site
04Site Impact
Complete site compromise: data theft, malware injection, defacement, or use as an attack platform.
Conditions required to exploit
05Prerequisites
No authentication required; victim must visit attacker-controlled page or click a link.
Key dates
06Disclosure timeline
January 21, 2025
CVE published
April 8, 2026
Record updated