ZeroHour

CVE-2026-81784

moderate

Unauthenticated PHP Object Injection in Wise Chat WordPress Plugin

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81784 is an unauthenticated PHP object injection flaw (CWE-502) in the Wise Chat WordPress plugin, affecting all versions up to and including 3.4. An unauthenticated attacker can reach the vulnerable deserialization sink over the network (CVSS:3.1/AV:N/PR:N/UI:N), causing crafted serialized input to be unserialized and attacker-influenced objects to be instantiated. Depending on the gadget chains present on a given site, this can escalate to arbitrary code execution or file operations, consistent with the 8.1 High score (high confidentiality, integrity, and availability impact); the high attack complexity (AC:H) indicates successful exploitation depends on conditions in the target environment. Any WordPress site running Wise Chat 3.4 or older is affected, and because chat functionality is typically exposed to anonymous visitors, exposure does not require logged-in users. There is currently no public proof-of-concept, no entry in CISA KEV, and no confirmed in-the-wild exploitation.

What to do: Sites running Wise Chat should upgrade immediately to the latest patched release (any version above 3.4) via the WordPress admin dashboard. Until patched, consider deactivating the plugin on internet-facing sites since the flaw requires no authentication. Because impact of PHP object injection can depend on gadget chains from other installed plugins/themes, also review whether your stack is likely to expose a high-impact POP chain.

Affected
Kainex Wise Chat (WordPress plugin)<= 3.4
Estimated exposure
moderate≈10,000–20,000+ WordPress sites (plugin active installs in the low tens of thousands) — Public WordPress.org data places Wise Chat's active installation count in the low tens of thousands, and the plugin runs site-wide with a component reachable by unauthenticated visitors.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.

Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.