CVE-2026-100506: WordPress WP Spell Check plugin <= 12.1 - PHP Object Injection vulnerability
Published Oct 5, 2026
·Updated
Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.
Affected Software
1 affected component
WP Spell Check WP Spell Check<=12.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Spell Check WordPress pluginto a version that resolves this vulnerability.Fixed in 12.2
Event History
Oct 5, 2026
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The attack vector is network-based, but exploitation requires high privileges. No user interaction is required.
2
What is the potential impact if exploitation succeeds?
The vulnerability is rated high severity with high impacts on confidentiality, integrity, and availability. It could enable unauthorized disclosure, modification, or disruption of affected systems.
3
Which versions are affected?
WP Spell Check versions through 12.1 are affected. The provided data does not identify a fixed version.