CVE-2026-97188 - String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor
CVE ID :CVE-2026-97188 Published : Oct. 7, 2026, 7:17 a.m. | 4 hours, 12 minutes ago Description :The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated...