CVE-2026-27060: WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection.
This issue affects ARMember Premium: from n/a before 7.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ARMember Premium pluginto a version that resolves this vulnerability.Fixed in 7.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27060?
The severity of CVE-2026-27060 is classified as high with a score of 8.8.
How do I fix CVE-2026-27060?
To fix CVE-2026-27060, update the ARMember Premium plugin to version 7.6 or later.
What type of vulnerability is CVE-2026-27060?
CVE-2026-27060 is a PHP Object Injection vulnerability resulting from deserialization of untrusted data.
Which versions of ARMember Premium are affected by CVE-2026-27060?
CVE-2026-27060 affects all versions of ARMember Premium prior to 7.6.
What impact does CVE-2026-27060 have on WordPress sites?
CVE-2026-27060 can lead to remote code execution due to the injection of malicious objects into the application.