CVE-2026-1542

CVE-2026-1542: Super Stage WP <= 1.0.1 - Unauthenticated PHP Object Injection

Vendor Unknown
Product Super Stage WP
Published February 28, 2026
Last update April 2, 2026

CVSS base score

What the vulnerability does

01Description

The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

Explanation of Vulnerability in Simple Terms

02Summary

Super Stage WP versions 1.0.1 and earlier contain an unknown vulnerability. Without access to the vendor's advisory or security details, the specific attack vector and impact cannot be determined. Site administrators should contact the vendor for clarification and apply any available patches immediately.

What an attacker can do

03Attacker Capabilities

Unknown; insufficient vulnerability details provided.

Potential impact on your site

04Site Impact

Unknown risk level; vendor clarification and patch status needed.

Conditions required to exploit

05Prerequisites

Unknown; insufficient vulnerability details provided.

Key dates

06Disclosure timeline

February 28, 2026 CVE published
April 2, 2026 Record updated