CVE-2026-87741 - ConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' Parameter
CVE ID :CVE-2026-87741 Published : Sept. 28, 2026, 8:17 p.m. | 1 hour, 58 minutes ago Description :The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX...