CVE-2026-49781CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Jun 15, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.Referenceshttps://patchstack.com/database/wordpress/plugin/suretriggers/vulnerability/wordpress-ottokit-plugin-1-1-27-php-object-injection-vulnerability?_s_id=cve