Описание
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.6.19 (исключая)
cpe:2.3:a:themepunch:slider_revolution:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 95%
0.15788
Средний
8.8 High
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 8.8
github
около 2 лет назад
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
EPSS
Процентиль: 95%
0.15788
Средний
8.8 High
CVSS3
Дефекты
CWE-502