CVE ID :CVE-2026-7654 Published : June 5, 2026, 11:16 p.m. | 1ย hour, 12ย minutes ago Description :The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()` functio
WordPress | PHP
Exploit
CVE-2026-7654
MITRE CVE High
Update to v7.0.18