A critical unauthenticated PHP Object Injection vulnerability has been identified in the WP Project Manager WordPress plugin affecting versions 4.0.6 and below. The vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to remote code execution or other severe impacts depending on available POP chains. The flaw is tracked as CVE-2026-78262 and has been reported via both the NVD and Patchstack databases. No authentication is required to exploit this vulnerability, significantly increasing its risk profile. Users of the affected plugin are advised to update to a patched version immediately. The vulnerability was disclosed through Patchstack's WordPress vulnerability database in addition to the NVD. The high severity rating reflects the unauthenticated nature of the attack vector and the potential for significant impact on affected WordPress installations.