CVE WATCH / VULNERABILITY DETAIL

CVE-2026-87741

HIGHCVSS 8.8NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fail

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-87741 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-87741

HIGHCVSS 8.8NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fail

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]