Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

PHP Object Injection in JS Archive List

IdentifiersCVE-2026-32513CWE-502· Deserialization of Untrusted Data

CVE-2026-32513 is a deserialization of untrusted data vulnerability in the Miguel Useche JS Archive List WordPress plugin (jquery-archive-list-widget). The issue affects JS Archive List versions through 6.1.7. According to the provided record, unsafe handling of untrusted serialized data allows PHP object injection. No specific vulnerable function or code path was provided in the available content.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can allow an authenticated attacker with low privileges to trigger PHP object injection over the network without user interaction. Depending on the gadget chains available in the target WordPress environment, this can result in severe compromise, including unauthorized access to sensitive data, modification of application state or content, arbitrary code execution in some environments, and denial of service. The provided CVSS v3.1 vector indicates high impact to confidentiality, integrity, and availability.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, disable and remove the JS Archive List plugin where feasible. Restrict access to plugin functionality to only trusted users, minimize low-privilege account access, and monitor for suspicious requests targeting plugin endpoints or parameters that may carry serialized input. Reducing installed plugins and libraries that expose usable PHP object gadget chains may also reduce exploitability, though this is not a substitute for patching.

Remediation

Patch, then assume compromise.

Update JS Archive List to a version newer than 6.1.7 if a vendor-fixed release is available. Because the provided content only states that versions through 6.1.7 are affected and does not identify a specific patched version, the exact fixed version is currently not available from the supplied data. Review vendor or Patchstack advisories for the definitive patched release and apply it promptly.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.