Events

800 events (filtered). · Last rule pass 11h ago. · 4 open / 4,675 resolved overall.

State: Open Resolved All
Critical new_committer_young_account Accordion and Accordion Slider (2k+ installs) Malicious 5mo ago
Slugaccordion-and-accordion-slider
Committeressentialplugin
Display nameessentialplugin
Member since2025-05-12
First commit at2025-05-15 07:40:24
Account age at first commit3
Commit count5
Active installs2,000
View raw JSON
{
    "slug": "accordion-and-accordion-slider",
    "committer": "essentialplugin",
    "display_name": "essentialplugin",
    "member_since": "2025-05-12",
    "first_commit_at": "2025-05-15 07:40:24",
    "account_age_at_first_commit": 3,
    "commit_count": 5,
    "active_installs": 2000
}
Critical new_committer_young_account Hero Banner Ultimate (— installs) Malicious 5mo ago
Slughero-banner-ultimate
Committeressentialplugin
Display nameessentialplugin
Member since2025-05-12
First commit at2025-06-19 15:32:40
Account age at first commit38
Commit count3
Active installs0
View raw JSON
{
    "slug": "hero-banner-ultimate",
    "committer": "essentialplugin",
    "display_name": "essentialplugin",
    "member_since": "2025-05-12",
    "first_commit_at": "2025-06-19 15:32:40",
    "account_age_at_first_commit": 38,
    "commit_count": 3,
    "active_installs": 0
}
Critical new_committer_young_account Styles For WP Pagenavi Addon – Better design for post pagination (— installs) Malicious 5mo ago
Slugstyles-for-wp-pagenavi-addon
Committeressentialplugin
Display nameessentialplugin
Member since2025-05-12
First commit at2025-05-24 12:11:36
Account age at first commit12
Commit count2
Active installs0
View raw JSON
{
    "slug": "styles-for-wp-pagenavi-addon",
    "committer": "essentialplugin",
    "display_name": "essentialplugin",
    "member_since": "2025-05-12",
    "first_commit_at": "2025-05-24 12:11:36",
    "account_age_at_first_commit": 12,
    "commit_count": 2,
    "active_installs": 0
}
Critical code_pattern Scroll To Top (20k+ installs) Malicious 5mo ago
Slugscroll-top
Patterncdnstaticsync.com
Kindioc:domain
Version1.5.3
Hit count1
First hit
File
scroll-top.php
Line
43
Snippet
'https://updates.cdnstaticsync.com/updates/?action=get_metadata&slug=scroll-top', //Metadata URL.
Explanation—
View raw JSON
{
    "slug": "scroll-top",
    "pattern": "cdnstaticsync.com",
    "kind": "ioc:domain",
    "version": "1.5.3",
    "hit_count": 1,
    "first_hit": {
        "file": "scroll-top.php",
        "line": 43,
        "snippet": "'https://updates.cdnstaticsync.com/updates/?action=get_metadata&slug=scroll-top', //Metadata URL."
    },
    "explanation": null
}
Critical code_pattern Scroll To Top (20k+ installs) Malicious 5mo ago
Slugscroll-top
Patternupdates.cdnstaticsync.com
Kindioc:domain
Version1.5.3
Hit count1
First hit
File
scroll-top.php
Line
43
Snippet
'https://updates.cdnstaticsync.com/updates/?action=get_metadata&slug=scroll-top', //Metadata URL.
Explanation—
View raw JSON
{
    "slug": "scroll-top",
    "pattern": "updates.cdnstaticsync.com",
    "kind": "ioc:domain",
    "version": "1.5.3",
    "hit_count": 1,
    "first_hit": {
        "file": "scroll-top.php",
        "line": 43,
        "snippet": "'https://updates.cdnstaticsync.com/updates/?action=get_metadata&slug=scroll-top', //Metadata URL."
    },
    "explanation": null
}
Critical code_pattern Scroll To Top (20k+ installs) Malicious 5mo ago
Slugscroll-top
Patterncdnstaticsync
Kindioc:code_pattern
Version1.5.3
Hit count1
First hit
File
scroll-top.php
Line
43
Snippet
'https://updates.cdnstaticsync.com/updates/?action=get_metadata&slug=scroll-top', //Metadata URL.
Explanation—
View raw JSON
{
    "slug": "scroll-top",
    "pattern": "cdnstaticsync",
    "kind": "ioc:code_pattern",
    "version": "1.5.3",
    "hit_count": 1,
    "first_hit": {
        "file": "scroll-top.php",
        "line": 43,
        "snippet": "'https://updates.cdnstaticsync.com/updates/?action=get_metadata&slug=scroll-top', //Metadata URL."
    },
    "explanation": null
}
Critical code_pattern Scroll To Top (20k+ installs) Malicious 5mo ago
Slugscroll-top
Patternpuc_update_hijack
Kindbuiltin
Version1.5.3
Hit count2
First hit
File
scroll-top.php
Line
42
Snippet
$UpdateChecker = PucFactory::buildUpdateChecker(
Explanationplugin calls `::buildUpdateChecker()` — the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal.
View raw JSON
{
    "slug": "scroll-top",
    "pattern": "puc_update_hijack",
    "kind": "builtin",
    "version": "1.5.3",
    "hit_count": 2,
    "first_hit": {
        "file": "scroll-top.php",
        "line": 42,
        "snippet": "$UpdateChecker = PucFactory::buildUpdateChecker("
    },
    "explanation": "plugin calls `::buildUpdateChecker()` \u2014 the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal."
}
Critical code_scan_delta Scroll To Top (20k+ installs) Malicious 5mo ago
Slugscroll-top
Previous version1.5.3
Current version1.5.3
New findings
PatternKindFileLineSnippetConfidence
puc_update_hijackbuiltinscroll-top.php42$UpdateChecker = PucFactory::buildUpdateChecker(high
puc_update_hijackbuiltinplugin-update-checker/Puc/v5p2/PucFactory.php54return self::buildUpdateChecker($metadataUrl, $fullPath, $slug, $checkPeriod, $optionName, $muPluginFile);high
New finding count2
View raw JSON
{
    "slug": "scroll-top",
    "previous_version": "1.5.3",
    "current_version": "1.5.3",
    "new_findings": [
        {
            "pattern": "puc_update_hijack",
            "kind": "builtin",
            "file": "scroll-top.php",
            "line": 42,
            "snippet": "$UpdateChecker = PucFactory::buildUpdateChecker(",
            "confidence": "high"
        },
        {
            "pattern": "puc_update_hijack",
            "kind": "builtin",
            "file": "plugin-update-checker/Puc/v5p2/PucFactory.php",
            "line": 54,
            "snippet": "return self::buildUpdateChecker($metadataUrl, $fullPath, $slug, $checkPeriod, $optionName, $muPluginFile);",
            "confidence": "high"
        }
    ],
    "new_finding_count": 2
}
Critical code_pattern W3 Total Cache (900k+ installs) Resolved 5mo ago
Slugw3-total-cache
Patternunserialize_after_remote_call
Kindbuiltin
Version2.9.4
Hit count2
First hit
File
lib/Minify/Minify/Cache/File.php
Line
148
Snippet
L146: $data = @file_get_contents($path . '_meta'); → L148: $data = @unserialize($data);
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "w3-total-cache",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.9.4",
    "hit_count": 2,
    "first_hit": {
        "file": "lib/Minify/Minify/Cache/File.php",
        "line": 148,
        "snippet": "L146: $data = @file_get_contents($path . '_meta');  \u2192  L148: $data = @unserialize($data);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern Ocean Extra (500k+ installs) Resolved 5mo ago
Slugocean-extra
Patternunserialize_after_remote_call
Kindbuiltin
Version2.5.5
Hit count3
First hit
File
includes/panel/classes/importers/class-settings-importer.php
Line
25
Snippet
L24: $raw = file_get_contents( $file ); → L25: $data = @unserialize( $raw, [ 'allowed_classes' => false ] );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "ocean-extra",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.5.5",
    "hit_count": 3,
    "first_hit": {
        "file": "includes/panel/classes/importers/class-settings-importer.php",
        "line": 25,
        "snippet": "L24: $raw  = file_get_contents( $file );  \u2192  L25: $data = @unserialize( $raw, [ 'allowed_classes' => false ]  );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern Duplicate Post (300k+ installs) Resolved 5mo ago
Slugcopy-delete-posts
Patternunserialize_after_remote_call
Kindbuiltin
Version1.5.3
Hit count1
First hit
File
analyst/src/Storage/FileStorage.php
Line
55
Snippet
L43: $encoded = @file_get_contents($filePath); → L55: return @unserialize($raw);
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "copy-delete-posts",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.5.3",
    "hit_count": 1,
    "first_hit": {
        "file": "analyst/src/Storage/FileStorage.php",
        "line": 55,
        "snippet": "L43: $encoded = @file_get_contents($filePath);  \u2192  L55: return @unserialize($raw);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Slugninja-forms
Patternunserialize_after_remote_call
Kindbuiltin
Version3.14.2
Hit count5
First hit
File
includes/Admin/Menus/ImportExport.php
Line
128
Snippet
L111: $import = file_get_contents( $_FILES[ 'nf_import_fields' ][ 'tmp_name' ] ); → L128: $return = unserialize($serializedValue,['allowed_classes'=>false]);
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "ninja-forms",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "3.14.2",
    "hit_count": 5,
    "first_hit": {
        "file": "includes/Admin/Menus/ImportExport.php",
        "line": 128,
        "snippet": "L111: $import = file_get_contents( $_FILES[ 'nf_import_fields' ][ 'tmp_name' ] );  \u2192  L128: $return = unserialize($serializedValue,['allowed_classes'=>false]);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern PixelYourSite – Your smart PIXEL (TAG) & API Manager (400k+ installs) Resolved 5mo ago
Slugpixelyoursite
Patternunserialize_after_remote_call
Kindbuiltin
Version11.2.0.4
Hit count3
First hit
File
includes/class-plugin-updater.php
Line
401
Snippet
L393: $request = wp_remote_post( $this->api_url, → L401: $request->sections = maybe_unserialize( $request->sections );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "pixelyoursite",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "11.2.0.4",
    "hit_count": 3,
    "first_hit": {
        "file": "includes/class-plugin-updater.php",
        "line": 401,
        "snippet": "L393: $request    = wp_remote_post( $this->api_url,  \u2192  L401: $request->sections = maybe_unserialize( $request->sections );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Slugkirki
Patternunserialize_after_remote_call
Kindbuiltin
Version5.2.3
Hit count3
First hit
File
customizer/packages/controls/tabs/edd/EDD_SL_Plugin_Updater.php
Line
545
Snippet
L527: $request = wp_remote_post( → L545: $request->sections = maybe_unserialize( $request->sections );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "kirki",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "5.2.3",
    "hit_count": 3,
    "first_hit": {
        "file": "customizer/packages/controls/tabs/edd/EDD_SL_Plugin_Updater.php",
        "line": 545,
        "snippet": "L527: $request = wp_remote_post(  \u2192  L545: $request->sections = maybe_unserialize( $request->sections );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider (500k+ installs) Resolved 5mo ago
Slugml-slider
Patternunserialize_after_remote_call
Kindbuiltin
Version3.108.0
Hit count3
First hit
File
lib/htmlpurifier/library/HTMLPurifier/DefinitionCache/Serializer.php
Line
73
Snippet
L73: return unserialize(file_get_contents($file)); → L73: return unserialize(file_get_contents($file));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "ml-slider",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "3.108.0",
    "hit_count": 3,
    "first_hit": {
        "file": "lib/htmlpurifier/library/HTMLPurifier/DefinitionCache/Serializer.php",
        "line": 73,
        "snippet": "L73: return unserialize(file_get_contents($file));  \u2192  L73: return unserialize(file_get_contents($file));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Slugfluent-smtp
Patternunserialize_after_remote_call
Kindbuiltin
Version2.2.95
Hit count1
First hit
File
app/Services/NotificationHelper.php
Line
328
Snippet
L312: $body = wp_remote_retrieve_body($response); → L328: $sendingTo = self::unserialize(Arr::get($logData, 'to'));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "fluent-smtp",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.2.95",
    "hit_count": 1,
    "first_hit": {
        "file": "app/Services/NotificationHelper.php",
        "line": 328,
        "snippet": "L312: $body = wp_remote_retrieve_body($response);  \u2192  L328: $sendingTo = self::unserialize(Arr::get($logData, 'to'));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern MailPoet – Newsletters, Email Marketing, and Automation (500k+ installs) Resolved 5mo ago
Slugmailpoet
Patternunserialize_after_remote_call
Kindbuiltin
Version5.23.2
Hit count2
First hit
File
lib/Doctrine/MetadataCache.php
Line
38
Snippet
L38: return unserialize((string)file_get_contents($this->getFilename($id))); → L38: return unserialize((string)file_get_contents($this->getFilename($id)));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "mailpoet",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "5.23.2",
    "hit_count": 2,
    "first_hit": {
        "file": "lib/Doctrine/MetadataCache.php",
        "line": 38,
        "snippet": "L38: return unserialize((string)file_get_contents($this->getFilename($id)));  \u2192  L38: return unserialize((string)file_get_contents($this->getFilename($id)));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Slugpost-smtp
Patternunserialize_after_remote_call
Kindbuiltin
Version3.9.1
Hit count3
First hit
File
includes/libs/HTMLPurifier/HTMLPurifier/DefinitionCache/Serializer.php
Line
73
Snippet
L73: return unserialize(file_get_contents($file)); → L73: return unserialize(file_get_contents($file));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "post-smtp",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "3.9.1",
    "hit_count": 3,
    "first_hit": {
        "file": "includes/libs/HTMLPurifier/HTMLPurifier/DefinitionCache/Serializer.php",
        "line": 73,
        "snippet": "L73: return unserialize(file_get_contents($file));  \u2192  L73: return unserialize(file_get_contents($file));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern SiteOrigin Widgets Bundle (400k+ installs) Resolved 5mo ago
Slugso-widgets-bundle
Patternunserialize_after_remote_call
Kindbuiltin
Version1.72.0
Hit count1
First hit
File
base/inc/lib/Less/Parser.php
Line
656
Snippet
L656: $cache = unserialize(file_get_contents($cache_file)); → L656: $cache = unserialize(file_get_contents($cache_file));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "so-widgets-bundle",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.72.0",
    "hit_count": 1,
    "first_hit": {
        "file": "base/inc/lib/Less/Parser.php",
        "line": 656,
        "snippet": "L656: $cache = unserialize(file_get_contents($cache_file));  \u2192  L656: $cache = unserialize(file_get_contents($cache_file));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern TranslatePress – Translate Multilingual sites with AI Translation (400k+ installs) Resolved 5mo ago
Slugtranslatepress-multilingual
Patternunserialize_after_remote_call
Kindbuiltin
Version3.1.7
Hit count3
First hit
File
includes/class-edd-sl-plugin-updater.php
Line
418
Snippet
L411: $request = wp_remote_post($this->api_url, array('timeout' => 15, 'sslverify' = → L418: $request->sections = maybe_unserialize($request->sections);
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "translatepress-multilingual",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "3.1.7",
    "hit_count": 3,
    "first_hit": {
        "file": "includes/class-edd-sl-plugin-updater.php",
        "line": 418,
        "snippet": "L411: $request = wp_remote_post($this->api_url, array('timeout' => 15, 'sslverify' =  \u2192  L418: $request->sections = maybe_unserialize($request->sections);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern Breeze Cache (300k+ installs) Resolved 5mo ago
Slugbreeze
Patternunserialize_after_remote_call
Kindbuiltin
Version2.4.5
Hit count1
First hit
File
inc/cache/execute-cache.php
Line
643
Snippet
L640: $cacheFile = file_get_contents( $path ); → L643: $datas = unserialize( $cacheFile );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "breeze",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.4.5",
    "hit_count": 1,
    "first_hit": {
        "file": "inc/cache/execute-cache.php",
        "line": 643,
        "snippet": "L640: $cacheFile = file_get_contents( $path );  \u2192  L643: $datas = unserialize( $cacheFile );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern Max Mega Menu (300k+ installs) Resolved 5mo ago
Slugmegamenu
Patternunserialize_after_remote_call
Kindbuiltin
Version3.8.1
Hit count2
First hit
File
classes/scss/1.11.1/src/Cache.php
Line
136
Snippet
L135: $c = file_get_contents($fileCache); → L136: $c = unserialize($c);
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "megamenu",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "3.8.1",
    "hit_count": 2,
    "first_hit": {
        "file": "classes/scss/1.11.1/src/Cache.php",
        "line": 136,
        "snippet": "L135: $c = file_get_contents($fileCache);  \u2192  L136: $c = unserialize($c);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) (300k+ installs) Resolved 5mo ago
Sluggoogle-analytics-dashboard-for-wp
Patternunserialize_after_remote_call
Kindbuiltin
Version9.1.3
Hit count2
First hit
File
includes/gutenberg/headline-tool/phpinsight/lib/PHPInsight/Sentiment.php
Line
230
Snippet
L229: $temp = file_get_contents( $fn ); → L230: $words = unserialize( trim( $temp ) );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "google-analytics-dashboard-for-wp",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "9.1.3",
    "hit_count": 2,
    "first_hit": {
        "file": "includes/gutenberg/headline-tool/phpinsight/lib/PHPInsight/Sentiment.php",
        "line": 230,
        "snippet": "L229: $temp  = file_get_contents( $fn );  \u2192  L230: $words = unserialize( trim( $temp ) );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern InfiniteWP Client (200k+ installs) Resolved 5mo ago
Slugiwp-client
Patternunserialize_after_remote_call
Kindbuiltin
Version1.13.5
Hit count1
First hit
File
backup/backup.php
Line
2,276
Snippet
L2276: $var = maybe_unserialize(file_get_contents($cache_file_base.'-info.tmp')); → L2276: $var = maybe_unserialize(file_get_contents($cache_file_base.'-info.tmp'));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "iwp-client",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.13.5",
    "hit_count": 1,
    "first_hit": {
        "file": "backup/backup.php",
        "line": 2276,
        "snippet": "L2276: $var = maybe_unserialize(file_get_contents($cache_file_base.'-info.tmp'));  \u2192  L2276: $var = maybe_unserialize(file_get_contents($cache_file_base.'-info.tmp'));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Slugultimate-member
Patternunserialize_after_remote_call
Kindbuiltin
Version2.11.3
Hit count7
First hit
File
includes/core/class-plugin-updater.php
Line
295
Snippet
L279: $request = json_decode( wp_remote_retrieve_body( $request ) ); → L295: $request = ( $request ) ? maybe_unserialize( $request ) : false;
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "ultimate-member",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.11.3",
    "hit_count": 7,
    "first_hit": {
        "file": "includes/core/class-plugin-updater.php",
        "line": 295,
        "snippet": "L279: $request = json_decode( wp_remote_retrieve_body( $request ) );  \u2192  L295: $request = ( $request ) ? maybe_unserialize( $request ) : false;"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_pattern Photo Gallery by 10Web – Mobile-Friendly Image Gallery (100k+ installs) Resolved 5mo ago
Slugphoto-gallery
Patternunserialize_after_remote_call
Kindbuiltin
Version1.8.39
Hit count1
First hit
File
wd/includes/overview.php
Line
44
Snippet
L41: $request = wp_remote_get(" http://api.wordpress.org/plugins/info/1.0/" . $plugin_wp_sl → L44: $body = unserialize($request['body']);
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak.
View raw JSON
{
    "slug": "photo-gallery",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.8.39",
    "hit_count": 1,
    "first_hit": {
        "file": "wd/includes/overview.php",
        "line": 44,
        "snippet": "L41: $request = wp_remote_get(\" http://api.wordpress.org/plugins/info/1.0/\" . $plugin_wp_sl  \u2192  L44: $body = unserialize($request['body']);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`/`file_get_contents`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak."
}
Critical code_scan_delta InfiniteWP Client (200k+ installs) Resolved 5mo ago
Slugiwp-client
Previous version1.13.5
Current version1.13.5
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinbackup/backup.php2,276L2276: $var = maybe_unserialize(file_get_contents($cache_file_base.'-info.tmp')); → L2276: $var = maybe_unserialize(file_get_contents($cache_file_base.'-info.tmp'));high
New finding count1
View raw JSON
{
    "slug": "iwp-client",
    "previous_version": "1.13.5",
    "current_version": "1.13.5",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "backup/backup.php",
            "line": 2276,
            "snippet": "L2276: $var = maybe_unserialize(file_get_contents($cache_file_base.'-info.tmp'));  \u2192  L2276: $var = maybe_unserialize(file_get_contents($cache_file_base.'-info.tmp'));",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Slugultimate-member
Previous version2.11.3
Current version2.11.3
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/core/class-plugin-updater.php295L279: $request = json_decode( wp_remote_retrieve_body( $request ) ); → L295: $request = ( $request ) ? maybe_unserialize( $request ) : false;high
unserialize_after_remote_callbuiltinincludes/core/class-plugin-updater.php331L326: wp_remote_retrieve_body( $request->$slug->get_version_check ) → L331: $request->$slug->get_version_check->banners = maybe_unserialize( $request->$slug->ghigh
unserialize_after_remote_callbuiltinincludes/core/class-plugin-updater.php335L326: wp_remote_retrieve_body( $request->$slug->get_version_check ) → L335: $request->$slug->get_version_check->icons = maybe_unserialize( $request->$slug->gethigh
unserialize_after_remote_callbuiltinincludes/core/class-plugin-updater.php453L439: $request = wp_remote_post( → L453: $request->sections = maybe_unserialize( $request->sections );high
unserialize_after_remote_callbuiltinincludes/core/class-plugin-updater.php460L449: $request = json_decode( wp_remote_retrieve_body( $request ) ); → L460: $request->banners = maybe_unserialize( $request->banners );high
unserialize_after_remote_callbuiltinincludes/core/class-plugin-updater.php464L449: $request = json_decode( wp_remote_retrieve_body( $request ) ); → L464: $request->icons = maybe_unserialize( $request->icons );high
unserialize_after_remote_callbuiltinincludes/admin/core/class-admin-settings.php3,094L3074: $request = json_decode( wp_remote_retrieve_body( $request ) ); → L3094: $request = ( $request ) ? maybe_unserialize( $request ) : false;high
New finding count7
View raw JSON
{
    "slug": "ultimate-member",
    "previous_version": "2.11.3",
    "current_version": "2.11.3",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/core/class-plugin-updater.php",
            "line": 295,
            "snippet": "L279: $request = json_decode( wp_remote_retrieve_body( $request ) );  \u2192  L295: $request = ( $request ) ? maybe_unserialize( $request ) : false;",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/core/class-plugin-updater.php",
            "line": 331,
            "snippet": "L326: wp_remote_retrieve_body( $request->$slug->get_version_check )  \u2192  L331: $request->$slug->get_version_check->banners = maybe_unserialize( $request->$slug->g",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/core/class-plugin-updater.php",
            "line": 335,
            "snippet": "L326: wp_remote_retrieve_body( $request->$slug->get_version_check )  \u2192  L335: $request->$slug->get_version_check->icons = maybe_unserialize( $request->$slug->get",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/core/class-plugin-updater.php",
            "line": 453,
            "snippet": "L439: $request = wp_remote_post(  \u2192  L453: $request->sections = maybe_unserialize( $request->sections );",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/core/class-plugin-updater.php",
            "line": 460,
            "snippet": "L449: $request = json_decode( wp_remote_retrieve_body( $request ) );  \u2192  L460: $request->banners = maybe_unserialize( $request->banners );",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/core/class-plugin-updater.php",
            "line": 464,
            "snippet": "L449: $request = json_decode( wp_remote_retrieve_body( $request ) );  \u2192  L464: $request->icons = maybe_unserialize( $request->icons );",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/admin/core/class-admin-settings.php",
            "line": 3094,
            "snippet": "L3074: $request = json_decode( wp_remote_retrieve_body( $request ) );  \u2192  L3094: $request = ( $request ) ? maybe_unserialize( $request ) : false;",
            "confidence": "high"
        }
    ],
    "new_finding_count": 7
}
Critical code_scan_delta Photo Gallery by 10Web – Mobile-Friendly Image Gallery (100k+ installs) Resolved 5mo ago
Slugphoto-gallery
Previous version1.8.39
Current version1.8.39
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinwd/includes/overview.php44L41: $request = wp_remote_get(" http://api.wordpress.org/plugins/info/1.0/" . $plugin_wp_sl → L44: $body = unserialize($request['body']);high
New finding count1
View raw JSON
{
    "slug": "photo-gallery",
    "previous_version": "1.8.39",
    "current_version": "1.8.39",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "wd/includes/overview.php",
            "line": 44,
            "snippet": "L41: $request = wp_remote_get(\" http://api.wordpress.org/plugins/info/1.0/\" . $plugin_wp_sl  \u2192  L44: $body = unserialize($request['body']);",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta Max Mega Menu (300k+ installs) Resolved 5mo ago
Slugmegamenu
Previous version3.8.1
Current version3.8.1
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinclasses/scss/1.11.1/src/Cache.php136L135: $c = file_get_contents($fileCache); → L136: $c = unserialize($c);high
unserialize_after_remote_callbuiltinclasses/scss/0.0.12/scss.inc.php4,352L4352: $imports = unserialize(file_get_contents($icache)); → L4352: $imports = unserialize(file_get_contents($icache));high
New finding count2
View raw JSON
{
    "slug": "megamenu",
    "previous_version": "3.8.1",
    "current_version": "3.8.1",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "classes/scss/1.11.1/src/Cache.php",
            "line": 136,
            "snippet": "L135: $c = file_get_contents($fileCache);  \u2192  L136: $c = unserialize($c);",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "classes/scss/0.0.12/scss.inc.php",
            "line": 4352,
            "snippet": "L4352: $imports = unserialize(file_get_contents($icache));  \u2192  L4352: $imports = unserialize(file_get_contents($icache));",
            "confidence": "high"
        }
    ],
    "new_finding_count": 2
}
Critical code_scan_delta Duplicate Post (300k+ installs) Resolved 5mo ago
Slugcopy-delete-posts
Previous version1.5.3
Current version1.5.3
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinanalyst/src/Storage/FileStorage.php55L43: $encoded = @file_get_contents($filePath); → L55: return @unserialize($raw);high
New finding count1
View raw JSON
{
    "slug": "copy-delete-posts",
    "previous_version": "1.5.3",
    "current_version": "1.5.3",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "analyst/src/Storage/FileStorage.php",
            "line": 55,
            "snippet": "L43: $encoded = @file_get_contents($filePath);  \u2192  L55: return @unserialize($raw);",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta Ad Inserter – Ad Manager & AdSense Ads (300k+ installs) Resolved 5mo ago
Slugad-inserter
Previous version2.8.13
Current version2.8.13
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinad-inserter.php7,294L7293: $response = wp_remote_post ($url, array ('body' => $request)); → L7294: $plugin_info = @unserialize ($response ['body']);high
New finding count1
View raw JSON
{
    "slug": "ad-inserter",
    "previous_version": "2.8.13",
    "current_version": "2.8.13",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "ad-inserter.php",
            "line": 7294,
            "snippet": "L7293: $response = wp_remote_post ($url, array ('body' => $request));  \u2192  L7294: $plugin_info = @unserialize ($response ['body']);",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) (300k+ installs) Resolved 5mo ago
Sluggoogle-analytics-dashboard-for-wp
Previous version9.1.3
Current version9.1.3
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/gutenberg/headline-tool/phpinsight/lib/PHPInsight/Sentiment.php230L229: $temp = file_get_contents( $fn ); → L230: $words = unserialize( trim( $temp ) );high
unserialize_after_remote_callbuiltinincludes/gutenberg/headline-tool/phpinsight/lib/PHPInsight/Sentiment.php360L359: $temp = file_get_contents( $fn ); → L360: $words = unserialize( trim( $temp ) );high
New finding count2
View raw JSON
{
    "slug": "google-analytics-dashboard-for-wp",
    "previous_version": "9.1.3",
    "current_version": "9.1.3",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/gutenberg/headline-tool/phpinsight/lib/PHPInsight/Sentiment.php",
            "line": 230,
            "snippet": "L229: $temp  = file_get_contents( $fn );  \u2192  L230: $words = unserialize( trim( $temp ) );",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/gutenberg/headline-tool/phpinsight/lib/PHPInsight/Sentiment.php",
            "line": 360,
            "snippet": "L359: $temp  = file_get_contents( $fn );  \u2192  L360: $words = unserialize( trim( $temp ) );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 2
}
Critical code_scan_delta SiteOrigin Widgets Bundle (400k+ installs) Resolved 5mo ago
Slugso-widgets-bundle
Previous version1.72.0
Current version1.72.0
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinbase/inc/lib/Less/Parser.php656L656: $cache = unserialize(file_get_contents($cache_file)); → L656: $cache = unserialize(file_get_contents($cache_file));high
New finding count1
View raw JSON
{
    "slug": "so-widgets-bundle",
    "previous_version": "1.72.0",
    "current_version": "1.72.0",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "base/inc/lib/Less/Parser.php",
            "line": 656,
            "snippet": "L656: $cache = unserialize(file_get_contents($cache_file));  \u2192  L656: $cache = unserialize(file_get_contents($cache_file));",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta TranslatePress – Translate Multilingual sites with AI Translation (400k+ installs) Resolved 5mo ago
Slugtranslatepress-multilingual
Previous version3.1.7
Current version3.1.7
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/class-edd-sl-plugin-updater.php418L411: $request = wp_remote_post($this->api_url, array('timeout' => 15, 'sslverify' = → L418: $request->sections = maybe_unserialize($request->sections);high
unserialize_after_remote_callbuiltinincludes/class-edd-sl-plugin-updater.php424L411: $request = wp_remote_post($this->api_url, array('timeout' => 15, 'sslverify' = → L424: $request->banners = maybe_unserialize($request->banners);high
unserialize_after_remote_callbuiltinincludes/class-edd-sl-plugin-updater.php483L475: $request = wp_remote_post($this->api_url, array('timeout' => 15, 'sslverif → L483: $version_info->sections = maybe_unserialize($version_info->sections);high
New finding count3
View raw JSON
{
    "slug": "translatepress-multilingual",
    "previous_version": "3.1.7",
    "current_version": "3.1.7",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/class-edd-sl-plugin-updater.php",
            "line": 418,
            "snippet": "L411: $request = wp_remote_post($this->api_url, array('timeout' => 15, 'sslverify' =  \u2192  L418: $request->sections = maybe_unserialize($request->sections);",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/class-edd-sl-plugin-updater.php",
            "line": 424,
            "snippet": "L411: $request = wp_remote_post($this->api_url, array('timeout' => 15, 'sslverify' =  \u2192  L424: $request->banners = maybe_unserialize($request->banners);",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/class-edd-sl-plugin-updater.php",
            "line": 483,
            "snippet": "L475: $request = wp_remote_post($this->api_url, array('timeout' => 15, 'sslverif  \u2192  L483: $version_info->sections = maybe_unserialize($version_info->sections);",
            "confidence": "high"
        }
    ],
    "new_finding_count": 3
}
Critical code_scan_delta Breeze Cache (300k+ installs) Resolved 5mo ago
Slugbreeze
Previous version2.4.5
Current version2.4.5
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltininc/cache/execute-cache.php643L640: $cacheFile = file_get_contents( $path ); → L643: $datas = unserialize( $cacheFile );high
New finding count1
View raw JSON
{
    "slug": "breeze",
    "previous_version": "2.4.5",
    "current_version": "2.4.5",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "inc/cache/execute-cache.php",
            "line": 643,
            "snippet": "L640: $cacheFile = file_get_contents( $path );  \u2192  L643: $datas = unserialize( $cacheFile );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Slugwpforms-lite
Patternunserialize_after_remote_call
Kindbuiltin
Version1.10.0.4
Hit count3
First hit
File
vendor_prefixed/ezyang/htmlpurifier/library/HTMLPurifier/DefinitionCache/Serializer.php
Line
71
Snippet
L71: return \unserialize(\file_get_contents($file)); → L71: return \unserialize(\file_get_contents($file));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this.
View raw JSON
{
    "slug": "wpforms-lite",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.10.0.4",
    "hit_count": 3,
    "first_hit": {
        "file": "vendor_prefixed/ezyang/htmlpurifier/library/HTMLPurifier/DefinitionCache/Serializer.php",
        "line": 71,
        "snippet": "L71: return \\unserialize(\\file_get_contents($file));  \u2192  L71: return \\unserialize(\\file_get_contents($file));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this."
}
Critical code_pattern UpdraftPlus: WP Backup & Migration Plugin (4M+ installs) Resolved 5mo ago
Slugupdraftplus
Patternunserialize_after_remote_call
Kindbuiltin
Version1.26.3
Hit count1
First hit
File
backup.php
Line
3,604
Snippet
L3604: $var = $updraftplus->unserialize(file_get_contents($cache_file_base.'-info.tmp')); → L3604: $var = $updraftplus->unserialize(file_get_contents($cache_file_base.'-info.tmp'));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this.
View raw JSON
{
    "slug": "updraftplus",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.26.3",
    "hit_count": 1,
    "first_hit": {
        "file": "backup.php",
        "line": 3604,
        "snippet": "L3604: $var = $updraftplus->unserialize(file_get_contents($cache_file_base.'-info.tmp'));  \u2192  L3604: $var = $updraftplus->unserialize(file_get_contents($cache_file_base.'-info.tmp'));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this."
}
Critical code_pattern Jetpack – WP Security, Backup, Speed, & Growth (3M+ installs) Resolved 5mo ago
Slugjetpack
Patternunserialize_after_remote_call
Kindbuiltin
Version15.7.1
Hit count2
First hit
File
jetpack_vendor/automattic/jetpack-waf/src/class-waf-stats.php
Line
151
Snippet
L137: $body = json_decode( wp_remote_retrieve_body( $response ) ); → L151: return maybe_unserialize( get_option( 'jetpack_protect_global_stats' ) );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this.
View raw JSON
{
    "slug": "jetpack",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "15.7.1",
    "hit_count": 2,
    "first_hit": {
        "file": "jetpack_vendor/automattic/jetpack-waf/src/class-waf-stats.php",
        "line": 151,
        "snippet": "L137: $body = json_decode( wp_remote_retrieve_body( $response ) );  \u2192  L151: return maybe_unserialize( get_option( 'jetpack_protect_global_stats' ) );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this."
}
Sluggoogle-analytics-for-wordpress
Patternunserialize_after_remote_call
Kindbuiltin
Version10.1.3
Hit count2
First hit
File
includes/gutenberg/headline-tool/phpinsight/lib/PHPInsight/Sentiment.php
Line
230
Snippet
L229: $temp = file_get_contents( $fn ); → L230: $words = unserialize( trim( $temp ) );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this.
View raw JSON
{
    "slug": "google-analytics-for-wordpress",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "10.1.3",
    "hit_count": 2,
    "first_hit": {
        "file": "includes/gutenberg/headline-tool/phpinsight/lib/PHPInsight/Sentiment.php",
        "line": 230,
        "snippet": "L229: $temp  = file_get_contents( $fn );  \u2192  L230: $words = unserialize( trim( $temp ) );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this."
}
Critical code_pattern Essential Addons for Elementor – Popular Elementor Templates & Widgets (1M+ installs) Resolved 5mo ago
Slugessential-addons-for-elementor-lite
Patternunserialize_after_remote_call
Kindbuiltin
Version6.6.2
Hit count1
First hit
File
includes/Classes/WPDeveloper_Plugin_Installer.php
Line
76
Snippet
L57: $response = wp_remote_post( → L76: return unserialize(wp_remote_retrieve_body($response));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this.
View raw JSON
{
    "slug": "essential-addons-for-elementor-lite",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "6.6.2",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/Classes/WPDeveloper_Plugin_Installer.php",
        "line": 76,
        "snippet": "L57: $response = wp_remote_post(  \u2192  L76: return unserialize(wp_remote_retrieve_body($response));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this."
}
Critical code_pattern Complianz GDPR/CCPA Cookie Consent Banner (1M+ installs) Resolved 5mo ago
Slugcomplianz-gdpr
Patternunserialize_after_remote_call
Kindbuiltin
Version7.4.6
Hit count3
First hit
File
upgrade/upgrade-to-pro.php
Line
285
Snippet
L279: $request = wp_remote_post( $this->api_url, array( 'timeout' => 15, 'sslverify' => tr → L285: $request->sections = maybe_unserialize( $request->sections );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this.
View raw JSON
{
    "slug": "complianz-gdpr",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "7.4.6",
    "hit_count": 3,
    "first_hit": {
        "file": "upgrade/upgrade-to-pro.php",
        "line": 285,
        "snippet": "L279: $request    = wp_remote_post( $this->api_url, array( 'timeout' => 15, 'sslverify' => tr  \u2192  L285: $request->sections = maybe_unserialize( $request->sections );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this."
}
Critical code_pattern Widgets for Google Reviews (1M+ installs) Resolved 5mo ago
Slugwp-reviews-plugin-for-google
Patternunserialize_after_remote_call
Kindbuiltin
Version13.2.9
Hit count1
First hit
File
trustindex-plugin.class.php
Line
7,088
Snippet
L7078: $wpResponse = wp_remote_post( → L7088: $wpRepoResponse = unserialize(wp_remote_retrieve_body($wpResponse));
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this.
View raw JSON
{
    "slug": "wp-reviews-plugin-for-google",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "13.2.9",
    "hit_count": 1,
    "first_hit": {
        "file": "trustindex-plugin.class.php",
        "line": 7088,
        "snippet": "L7078: $wpResponse = wp_remote_post(  \u2192  L7088: $wpRepoResponse = unserialize(wp_remote_retrieve_body($wpResponse));"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this."
}
Critical code_pattern Polylang (800k+ installs) Resolved 5mo ago
Slugpolylang
Patternunserialize_after_remote_call
Kindbuiltin
Version3.8.2
Hit count3
First hit
File
src/install/plugin-updater.php
Line
635
Snippet
L617: $request = wp_remote_post( → L635: $request->sections = maybe_unserialize( $request->sections );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this.
View raw JSON
{
    "slug": "polylang",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "3.8.2",
    "hit_count": 3,
    "first_hit": {
        "file": "src/install/plugin-updater.php",
        "line": 635,
        "snippet": "L617: $request = wp_remote_post(  \u2192  L635: $request->sections = maybe_unserialize( $request->sections );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this."
}
Slugpopup-maker
Patternunserialize_after_remote_call
Kindbuiltin
Version1.22.0
Hit count3
First hit
File
classes/Extension/Updater.php
Line
670
Snippet
L652: $request = wp_remote_get(// Uses wp_remote_post() in EDD Sample. → L670: $request->sections = maybe_unserialize( $request->sections );
Explanationa remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file — classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this.
View raw JSON
{
    "slug": "popup-maker",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.22.0",
    "hit_count": 3,
    "first_hit": {
        "file": "classes/Extension/Updater.php",
        "line": 670,
        "snippet": "L652: $request = wp_remote_get(// Uses wp_remote_post() in EDD Sample.  \u2192  L670: $request->sections = maybe_unserialize( $request->sections );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*`/`curl_exec`) is followed by `unserialize`/`maybe_unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget used by EP and most WP supply-chain backdoors. Legit plugins essentially never do this."
}
Slugpost-smtp
Previous version3.9.1
Current version3.9.1
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/libs/HTMLPurifier/HTMLPurifier/DefinitionCache/Serializer.php73L73: return unserialize(file_get_contents($file)); → L73: return unserialize(file_get_contents($file));high
unserialize_after_remote_callbuiltinincludes/libs/HTMLPurifier/HTMLPurifier/ConfigSchema.php72L71: $contents = file_get_contents(HTMLPURIFIER_PREFIX . '/HTMLPurifier/ConfigSchema/sc → L72: $r = unserialize($contents);high
unserialize_after_remote_callbuiltinincludes/libs/HTMLPurifier/HTMLPurifier/EntityLookup.php26L26: $this->table = unserialize(file_get_contents($file)); → L26: $this->table = unserialize(file_get_contents($file));high
New finding count3
View raw JSON
{
    "slug": "post-smtp",
    "previous_version": "3.9.1",
    "current_version": "3.9.1",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/libs/HTMLPurifier/HTMLPurifier/DefinitionCache/Serializer.php",
            "line": 73,
            "snippet": "L73: return unserialize(file_get_contents($file));  \u2192  L73: return unserialize(file_get_contents($file));",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/libs/HTMLPurifier/HTMLPurifier/ConfigSchema.php",
            "line": 72,
            "snippet": "L71: $contents = file_get_contents(HTMLPURIFIER_PREFIX . '/HTMLPurifier/ConfigSchema/sc  \u2192  L72: $r = unserialize($contents);",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/libs/HTMLPurifier/HTMLPurifier/EntityLookup.php",
            "line": 26,
            "snippet": "L26: $this->table = unserialize(file_get_contents($file));  \u2192  L26: $this->table = unserialize(file_get_contents($file));",
            "confidence": "high"
        }
    ],
    "new_finding_count": 3
}
Critical code_scan_delta Kirki – Freeform Page Builder, Website Builder & Customizer (500k+ installs) Suspicious 5mo ago
Slugkirki
Previous version5.2.3
Current version5.2.3
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltincustomizer/packages/controls/tabs/edd/EDD_SL_Plugin_Updater.php545L527: $request = wp_remote_post( → L545: $request->sections = maybe_unserialize( $request->sections );high
unserialize_after_remote_callbuiltincustomizer/packages/controls/tabs/edd/EDD_SL_Plugin_Updater.php551L542: $request = json_decode( wp_remote_retrieve_body( $request ) ); → L551: $request->banners = maybe_unserialize( $request->banners );high
unserialize_after_remote_callbuiltincustomizer/packages/controls/tabs/edd/EDD_SL_Plugin_Updater.php555L542: $request = json_decode( wp_remote_retrieve_body( $request ) ); → L555: $request->icons = maybe_unserialize( $request->icons );high
New finding count3
View raw JSON
{
    "slug": "kirki",
    "previous_version": "5.2.3",
    "current_version": "5.2.3",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "customizer/packages/controls/tabs/edd/EDD_SL_Plugin_Updater.php",
            "line": 545,
            "snippet": "L527: $request = wp_remote_post(  \u2192  L545: $request->sections = maybe_unserialize( $request->sections );",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "customizer/packages/controls/tabs/edd/EDD_SL_Plugin_Updater.php",
            "line": 551,
            "snippet": "L542: $request = json_decode( wp_remote_retrieve_body( $request ) );  \u2192  L551: $request->banners = maybe_unserialize( $request->banners );",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "customizer/packages/controls/tabs/edd/EDD_SL_Plugin_Updater.php",
            "line": 555,
            "snippet": "L542: $request = json_decode( wp_remote_retrieve_body( $request ) );  \u2192  L555: $request->icons = maybe_unserialize( $request->icons );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 3
}
Critical code_scan_delta Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider (500k+ installs) Resolved 5mo ago
Slugml-slider
Previous version3.108.0
Current version3.108.0
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinlib/htmlpurifier/library/HTMLPurifier/DefinitionCache/Serializer.php73L73: return unserialize(file_get_contents($file)); → L73: return unserialize(file_get_contents($file));high
unserialize_after_remote_callbuiltinlib/htmlpurifier/library/HTMLPurifier/ConfigSchema.php72L71: $contents = file_get_contents(HTMLPURIFIER_PREFIX . '/HTMLPurifier/ConfigSchema/sc → L72: $r = unserialize($contents);high
unserialize_after_remote_callbuiltinlib/htmlpurifier/library/HTMLPurifier/EntityLookup.php26L26: $this->table = unserialize(file_get_contents($file)); → L26: $this->table = unserialize(file_get_contents($file));high
New finding count3
View raw JSON
{
    "slug": "ml-slider",
    "previous_version": "3.108.0",
    "current_version": "3.108.0",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "lib/htmlpurifier/library/HTMLPurifier/DefinitionCache/Serializer.php",
            "line": 73,
            "snippet": "L73: return unserialize(file_get_contents($file));  \u2192  L73: return unserialize(file_get_contents($file));",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "lib/htmlpurifier/library/HTMLPurifier/ConfigSchema.php",
            "line": 72,
            "snippet": "L71: $contents = file_get_contents(HTMLPURIFIER_PREFIX . '/HTMLPurifier/ConfigSchema/sc  \u2192  L72: $r = unserialize($contents);",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "lib/htmlpurifier/library/HTMLPurifier/EntityLookup.php",
            "line": 26,
            "snippet": "L26: $this->table = unserialize(file_get_contents($file));  \u2192  L26: $this->table = unserialize(file_get_contents($file));",
            "confidence": "high"
        }
    ],
    "new_finding_count": 3
}
Slugfluent-smtp
Previous version2.2.95
Current version2.2.95
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinapp/Services/NotificationHelper.php328L312: $body = wp_remote_retrieve_body($response); → L328: $sendingTo = self::unserialize(Arr::get($logData, 'to'));high
New finding count1
View raw JSON
{
    "slug": "fluent-smtp",
    "previous_version": "2.2.95",
    "current_version": "2.2.95",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "app/Services/NotificationHelper.php",
            "line": 328,
            "snippet": "L312: $body = wp_remote_retrieve_body($response);  \u2192  L328: $sendingTo = self::unserialize(Arr::get($logData, 'to'));",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta MailPoet – Newsletters, Email Marketing, and Automation (500k+ installs) Resolved 5mo ago
Slugmailpoet
Previous version5.23.2
Current version5.23.2
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinlib/Doctrine/MetadataCache.php38L38: return unserialize((string)file_get_contents($this->getFilename($id))); → L38: return unserialize((string)file_get_contents($this->getFilename($id)));high
unserialize_after_remote_callbuiltinlib/Doctrine/MetadataCache.php48L38: return unserialize((string)file_get_contents($this->getFilename($id))); → L48: $classMetadata = unserialize((string)file_get_contents($filename));high
New finding count2
View raw JSON
{
    "slug": "mailpoet",
    "previous_version": "5.23.2",
    "current_version": "5.23.2",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "lib/Doctrine/MetadataCache.php",
            "line": 38,
            "snippet": "L38: return unserialize((string)file_get_contents($this->getFilename($id)));  \u2192  L38: return unserialize((string)file_get_contents($this->getFilename($id)));",
            "confidence": "high"
        },
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "lib/Doctrine/MetadataCache.php",
            "line": 48,
            "snippet": "L38: return unserialize((string)file_get_contents($this->getFilename($id)));  \u2192  L48: $classMetadata = unserialize((string)file_get_contents($filename));",
            "confidence": "high"
        }
    ],
    "new_finding_count": 2
}