Required CVE Record Information
Description
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Credits
- Nguyen Huu Do finder
- WPScan coordinator
References 1 Total
- https://wpscan.com/vulnerability/fb8791f5-2879-431e-9afc-06d5839e4b9d exploitvdb-entrytechnical-description
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 1 Total
- https://wpscan.com/vulnerability/fb8791f5-2879-431e-9afc-06d5839e4b9d exploitvdb-entrytechnical-descriptionx_transferred