Wordpress Alert: PHP object injection through unsafe deserialization

A plugin unserializes untrusted input into PHP objects. Available object behaviors may be abused, sometimes with severe consequences.

What it looks like

A plugin unserializes untrusted input into PHP objects.

Why it matters

Available object behaviors may be abused, sometimes with severe consequences.

What to check

Audit deserialization of request, cookie, and imported data.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP deserialization guidance.