What CVE-2026-87741 Establishes
The CVE entry describes ConvertPlus, a WordPress plugin, vulnerable to deserialization of untrusted data in all versions up to and including 3.6.3. The cp_display_preview_modal AJAX action guards its nonce check behind an isset() test, so the check fails open when the cp_admin_page_nonce parameter is omitted entirely, and the callback performs no capability check. The style parameter is passed through sanitize_text_field(), which does not remove shortcode delimiters, so an attacker can append a second, fully controlled [smile_modal] shortcode. When do_shortcode() evaluates it, smile_modal_popup() hands base64-decoded, attacker-supplied bytes to maybe_unserialize() with no allowed_classes restriction. Authenticated attackers with Subscriber-level access and above can inject a PHP object.
Conditional Impact: Why the POP Chain Matters
Injecting a PHP object is only half of a deserialization attack. The disclosure states that no known POP chain exists in the vulnerable software, which means CVE-2026-87741 has no impact on its own. If another plugin or theme installed on the target site contains a POP chain, the injected object can trigger it, and the outcome depends entirely on that chain, ranging from file deletion and data theft to code execution. Every WordPress site runs a different mix of third-party code, so the same vulnerable ConvertPlus version can be harmless on one site and catastrophic on the next. That uncertainty is exactly why an unpatched deserialization flaw cannot be left in place.
How BitFire Blocks Automated Exploit Delivery
This exploit cannot fire without a request: an attacker must call the cp_display_preview_modal AJAX action with crafted parameters. That is precisely the delivery path BitFire FREE Bot Protection controls. BitFire evaluates who is making each request before WordPress processes it. Unknown or restricted bots are limited to safe viewing and cannot call sensitive APIs or send POST data; scripts posing as browsers must pass lightweight JavaScript verification; and known scanning tools such as WPScan, sqlmap, nikto, and nmap are blocked outright. Automated delivery of this PHP object injection is stopped before the vulnerable code runs. Explicitly allowlisted clients and successfully verified real browsers are not categorically stopped, which is why patching to a fixed release remains essential.
If Your Site Was Affected, Investigate for Persistence.
Update ConvertPlus to 3.6.4 immediately; the vendor identifies this release as fixed. Patching closes the vulnerable action, but it does not prove your site is clean. Any site that ran version 3.6.3 or earlier should assume exploitation was possible and run BitFire Threat Hunter, a thorough post-compromise investigation that searches for backdoor WordPress administrator accounts, hidden database triggers, WordPress and server cron persistence, must-use plugins and startup-chain modifications, long-running PHP processes, and droppers that can restore malware or reinfect the site. Remove every persistence mechanism Threat Hunter discovers and rotate administrator credentials. An absence of obvious malicious files is not proof that an attacker never got in.
Conclusion: Layered Defense, Patched Fast
CVE-2026-87741 turns a preview feature into a PHP object injection primitive for any Subscriber-level account, with consequences that depend on the POP chains your other plugins and themes provide. Do not wait to find out what those chains enable. Upgrade to ConvertPlus 3.6.4, install BitFire FREE and enable Bot Protection to stop automated exploit delivery at the request layer, and run Threat Hunter if the vulnerable version was ever live on your site. Automated attacks move in seconds; your defenses should already be in place.