How BitFire Protects Against CVE-2026-87741: ConvertPlus Deserialization Of…

WordPress vulnerability research

BitFire Bot Protection blocks the automated AJAX delivery CVE-2026-87741 depends on, stopping ConvertPlus PHP object injection before vulnerable code runs.

Authenticated (Subscriber+) High severity (CVSS 8.8) Impact requires a POP chain Deserialization of Untrusted Data
BitFire · Vulnerability advisoryResearch published
AdvisoryCVE-2026-87741
ComponentConvertPlus
Executive summary

What WordPress administrators need to know

ConvertPlus, a WordPress plugin, is vulnerable to deserialization of untrusted data in all versions up to and including 3.6.3. Through the cp_display_preview_modal AJAX action, an authenticated attacker with Subscriber-level access or higher can reach an unrestricted PHP unserialization call and inject a PHP object, despite a nonce guard that fails open when its parameter is omitted. The disclosure states the flaw has no impact unless another plugin or theme on the site supplies a POP chain, in which case attackers may delete files, retrieve sensitive data, or execute code. BitFire FREE Bot Protection blocks the automated AJAX delivery this exploit requires, and 3.6.4 removes the flaw itself.

At a glance

Key facts

  • All ConvertPlus versions up to and including 3.6.3 are affected; the vendor identifies 3.6.4 as fixed.
  • The cp_display_preview_modal AJAX action fails open when cp_admin_page_nonce is omitted and performs no capability check.
  • sanitize_text_field() leaves shortcode delimiters intact, enabling a fully attacker-controlled second [smile_modal] shortcode.
  • smile_modal_popup() passes base64-decoded attacker bytes to maybe_unserialize() with no allowed_classes restriction.
  • No known POP chain exists in the vulnerable software; impact requires another plugin or theme containing a POP chain.
  • BitFire FREE Bot Protection blocks the automated AJAX requests this exploit depends on.
01
Vulnerability overview

Understand the exposure

The affected component, attack path, and practical risk for WordPress websites.

Affected componentConvertPlus
Potential reachNot publicly reported installations
Attack techniquedeserialization of untrusted data
Published2026-09-29
BitFire Bot Protection classifies and blocks the automated AJAX requests CVE-2026-87741 depends on, stopping exploit delivery before the vulnerable ConvertPlus code ever runs.
02
Technical analysis

How the vulnerability works

Research details, affected versions, exploitation behavior, and remediation guidance.

What CVE-2026-87741 Establishes

The CVE entry describes ConvertPlus, a WordPress plugin, vulnerable to deserialization of untrusted data in all versions up to and including 3.6.3. The cp_display_preview_modal AJAX action guards its nonce check behind an isset() test, so the check fails open when the cp_admin_page_nonce parameter is omitted entirely, and the callback performs no capability check. The style parameter is passed through sanitize_text_field(), which does not remove shortcode delimiters, so an attacker can append a second, fully controlled [smile_modal] shortcode. When do_shortcode() evaluates it, smile_modal_popup() hands base64-decoded, attacker-supplied bytes to maybe_unserialize() with no allowed_classes restriction. Authenticated attackers with Subscriber-level access and above can inject a PHP object.

Conditional Impact: Why the POP Chain Matters

Injecting a PHP object is only half of a deserialization attack. The disclosure states that no known POP chain exists in the vulnerable software, which means CVE-2026-87741 has no impact on its own. If another plugin or theme installed on the target site contains a POP chain, the injected object can trigger it, and the outcome depends entirely on that chain, ranging from file deletion and data theft to code execution. Every WordPress site runs a different mix of third-party code, so the same vulnerable ConvertPlus version can be harmless on one site and catastrophic on the next. That uncertainty is exactly why an unpatched deserialization flaw cannot be left in place.

How BitFire Blocks Automated Exploit Delivery

This exploit cannot fire without a request: an attacker must call the cp_display_preview_modal AJAX action with crafted parameters. That is precisely the delivery path BitFire FREE Bot Protection controls. BitFire evaluates who is making each request before WordPress processes it. Unknown or restricted bots are limited to safe viewing and cannot call sensitive APIs or send POST data; scripts posing as browsers must pass lightweight JavaScript verification; and known scanning tools such as WPScan, sqlmap, nikto, and nmap are blocked outright. Automated delivery of this PHP object injection is stopped before the vulnerable code runs. Explicitly allowlisted clients and successfully verified real browsers are not categorically stopped, which is why patching to a fixed release remains essential.

If Your Site Was Affected, Investigate for Persistence.

Update ConvertPlus to 3.6.4 immediately; the vendor identifies this release as fixed. Patching closes the vulnerable action, but it does not prove your site is clean. Any site that ran version 3.6.3 or earlier should assume exploitation was possible and run BitFire Threat Hunter, a thorough post-compromise investigation that searches for backdoor WordPress administrator accounts, hidden database triggers, WordPress and server cron persistence, must-use plugins and startup-chain modifications, long-running PHP processes, and droppers that can restore malware or reinfect the site. Remove every persistence mechanism Threat Hunter discovers and rotate administrator credentials. An absence of obvious malicious files is not proof that an attacker never got in.

Conclusion: Layered Defense, Patched Fast

CVE-2026-87741 turns a preview feature into a PHP object injection primitive for any Subscriber-level account, with consequences that depend on the POP chains your other plugins and themes provide. Do not wait to find out what those chains enable. Upgrade to ConvertPlus 3.6.4, install BitFire FREE and enable Bot Protection to stop automated exploit delivery at the request layer, and run Threat Hunter if the vulnerable version was ever live on your site. Automated attacks move in seconds; your defenses should already be in place.

03
Zero-day protection

Protection from the first exploit request

BitFire protects WordPress servers on day zero—before a vulnerability is publicly known and before other vendors have time to develop signatures or patches.

01 · VerifyStop unknown clients

Bot controls and browser verification stop untrusted automated clients before previously unknown exploit code reaches WordPress.

02 · DetectBlock malicious behavior

General WAF protections identify dangerous request behavior and hostile payloads without waiting for a vulnerability-specific signature.

03 · PreventContain attacks at runtime

RASP follows execution inside PHP and prevents unauthorized changes to protected files, accounts, and database content.

BitFire · WordPress protectionZero-day ready
BitFire combines verified-client controls, behavior-based WAF detection, and runtime RASP enforcement to protect WordPress before an exploit has a name, CVE, signature, or vendor patch.
About the author

Cory Marsh

Cory has more than 20 years of internet security experience and is a lead developer on the BitFire project.

Read BitFire security research →
Protect your WordPress website

Add protection before the next exploit arrives.

BitFire combines bot controls, request inspection, malware detection, and runtime protection in one WordPress security platform.

Protect my site free →