Leafcolor Applay Shortcodes Plugin PHP Object Injection Vulnerability

Vulnerability

A deserialization vulnerability allowing object injection has been identified in the Leafcolor Applay Shortcodes WordPress plugin, affecting versions through 3.7. This vulnerability arises from the deserialization of untrusted data, which could potentially lead to various types of code injection, including PHP object injection.

Impact

Exploitation of this vulnerability could allow for PHP object injection, which, if a suitable property-oriented programming (POP) chain is available, could be leveraged to execute arbitrary code, inject malicious SQL, traverse the file system in an unauthorized manner, cause a denial-of-service condition, or achieve other harmful effects.

Remediation

Users are advised to update to a version of the Leafcolor Applay Shortcodes WordPress plugin that is later than 3.7. For those seeking immediate protection, Patchstack has released a mitigation rule that can be applied until an official patch is available.

Added: Feb 20, 2026, 7:26 PM
Updated: Feb 20, 2026, 7:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.7
remediation
0.0
relevance
3.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.