Description
The Read More & Accordion WordPress plugin before 3.2.7 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44059 | The Read More & Accordion WordPress plugin before 3.2.7 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-09-16T15:43:45.758Z
Reserved: 2023-06-23T16:49:48.588Z
Link: CVE-2023-3392
Updated: 2024-08-02T06:55:03.465Z
Status : Modified
Published: 2023-10-16T09:15:10.337
Modified: 2024-11-21T08:17:10.307
Link: CVE-2023-3392
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD