CVE-2026-94678: WordPress Go Live Update Urls plugin <= 7.0.8 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
Affected Software
1 affected component
WordPress Go Live Update Urls<=7.0.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Go Live Update Urls pluginto a version that resolves this vulnerability.Fixed in 7.1.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Contributor-level access or higher. No user interaction is required once that access is available.
2
Can this be exploited remotely?
Yes. The CVSS vector indicates network-based exploitation with low attack complexity, but the attacker must first have the required Contributor privileges.
3
What is the potential impact if exploitation succeeds?
The reported severity vector indicates high impact to confidentiality, integrity, and availability. This could expose data, allow unauthorized changes, or disrupt the affected WordPress site.