CVE-2026-0677

CVE-2026-0677: WordPress TotalContest Lite plugin <= 2.9.1 - PHP Object Injection vulnerability

Vendor Totalsuite
Product TotalContest Lite
Weakness CWE-502 · Unsafe deserialization
Published March 20, 2026
Last update June 10, 2026

CVSS base score

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injection.This issue affects TotalContest Lite: from n/a through <= 2.9.1.

Explanation of Vulnerability in Simple Terms

02Summary

TotalContest Lite versions 2.9.1 and earlier contain a deserialization vulnerability that allows attackers to execute arbitrary code by sending specially crafted serialized data. The vulnerability exists in how the plugin processes untrusted input without proper validation. Successful exploitation requires network access but the exact attack prerequisites are unclear due to incomplete CVSS data.

What an attacker can do

03Attacker Capabilities

Execute arbitrary code on the site by sending malicious serialized data to the plugin.

Potential impact on your site

04Site Impact

An attacker could run their own code on your site, potentially compromising user data, modifying content, or taking full control.

Conditions required to exploit

05Prerequisites

Network access to the vulnerable plugin; specific authentication or user interaction requirements unknown.

Key dates

06Disclosure timeline

March 20, 2026 CVE published
June 10, 2026 Record updated

Related vulnerabilities

08Related CVE