VYPR

Codepress Admin Columns

by WordPress

CVEs (1)

  • CVE-2026-7654HigJun 5, 2026
    risk 0.57cvss 8.8epss

    The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()`…