Описание
The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.
EPSS
Процентиль: 42%
0.00524
Низкий
9 Critical
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 9
github
2 дня назад
The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.
EPSS
Процентиль: 42%
0.00524
Низкий
9 Critical
CVSS3
Дефекты
CWE-94