CVE-2026-14602: Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter
The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Remote API WordPress pluginto a version that resolves this vulnerability.Fixed in 0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14602?
CVE-2026-14602 has a severity score of 9, indicating a critical vulnerability.
How do I fix CVE-2026-14602?
To fix CVE-2026-14602, update the Remote API plugin to version 0.3 or later.
What type of vulnerability is CVE-2026-14602?
CVE-2026-14602 is a code injection vulnerability that allows unauthenticated PHP Object Injection.
Who is affected by CVE-2026-14602?
Any user with the Remote API WordPress plugin version 0.2 or earlier installed is affected by CVE-2026-14602.
What could happen if CVE-2026-14602 is exploited?
Exploiting CVE-2026-14602 may lead to remote code execution on the affected WordPress site.