CVE-2026-1542: Unknown Super Stage Wp
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Affected products
- Unknown Super Stage Wp: up to and including 1.0.1
Published 2026-02-28. Last modified 2026-06-17.