CVE-2026-94683: WordPress DesignSetGo plugin <= 2.8.0 - PHP Object Injection vulnerability
Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress DesignSetGo pluginto a version that resolves this vulnerability.Fixed in 2.8.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Contributor-level access to a WordPress site running an affected DesignSetGo version. No user interaction is required, and the vulnerability is remotely reachable.
What impact could successful exploitation have?
The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability. The available data identifies the issue as PHP object injection but does not specify the exact exploitation outcome or required gadget chain.
How can I determine whether my site is affected?
Check whether the DesignSetGo plugin is installed and whether its version is 2.8.0 or earlier. Sites without the plugin, or with a version newer than 2.8.0, are not identified as affected by the provided data.