CVE-2026-97283: WordPress Advanced Post Manager plugin <= 4.5.5 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/advanced-post-managerto a version that resolves this vulnerability.Fixed in 4.5.6
Event History
Frequently Asked Questions
Which installations are affected?
Advanced Post Manager versions through 4.5.5 are affected. The available data does not identify a fixed version.
Can this be exploited remotely without authentication or user interaction?
Yes. The listed vector is network-accessible with low attack complexity, requires no privileges, and requires no user interaction.
What impact could successful exploitation have?
The vulnerability is rated critical with high impact to confidentiality, integrity, and availability. It is classified as PHP object injection through deserialization of untrusted data.