TotalSuite TotalContest Lite PHP Object Injection Vulnerability

Vulnerability

A deserialization vulnerability allowing object injection has been identified in the TotalSuite TotalContest Lite WordPress plugin, affecting versions through 2.9.1. This vulnerability arises from the improper handling of untrusted data, which could lead to PHP object injection.

Impact

Exploitation of this vulnerability could allow a malicious actor to inject objects that, if manipulated correctly, could be used to execute arbitrary code, perform SQL injection, traverse directories in an unauthorized manner, cause a denial-of-service, or exploit other vulnerabilities that rely on a crafted object payload.

Remediation

Users are advised to update the TotalContest Lite plugin to the latest version. If an update is not possible, consult with your hosting provider or web developer for assistance.

Added: Mar 20, 2026, 10:22 AM
Updated: Mar 20, 2026, 10:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.7
remediation
0.0
relevance
4.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.