CVE-2026-81784
moderateUnauthenticated PHP Object Injection in Wise Chat WordPress Plugin
CVE-2026-81784 is an unauthenticated PHP object injection flaw (CWE-502) in the Wise Chat WordPress plugin, affecting all versions up to and including 3.4. An unauthenticated attacker can reach the vulnerable deserialization sink over the network (CVSS:3.1/AV:N/PR:N/UI:N), causing crafted serialized input to be unserialized and attacker-influenced objects to be instantiated. Depending on the gadget chains present on a given site, this can escalate to arbitrary code execution or file operations, consistent with the 8.1 High score (high confidentiality, integrity, and availability impact); the high attack complexity (AC:H) indicates successful exploitation depends on conditions in the target environment. Any WordPress site running Wise Chat 3.4 or older is affected, and because chat functionality is typically exposed to anonymous visitors, exposure does not require logged-in users. There is currently no public proof-of-concept, no entry in CISA KEV, and no confirmed in-the-wild exploitation.
What to do: Sites running Wise Chat should upgrade immediately to the latest patched release (any version above 3.4) via the WordPress admin dashboard. Until patched, consider deactivating the plugin on internet-facing sites since the flaw requires no authentication. Because impact of PHP object injection can depend on gadget chains from other installed plugins/themes, also review whether your stack is likely to expose a high-impact POP chain.
| Kainex Wise Chat (WordPress plugin) | <= 3.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.