Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jcm-jwvc-6vhm

Опубликовано: 30 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.

EPSS

Процентиль: 42%
0.00524
Низкий

9 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9
nvd
2 дня назад

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.

EPSS

Процентиль: 42%
0.00524
Низкий

9 Critical

CVSS3

Дефекты

CWE-94